Impact
A permissions oversight incorrectly allows certain applications to read or write data on removable storage devices without the user’s explicit consent. This flaw corresponds to CWE-276, where an operating‑system privilege is incorrectly granted, enabling attackers or unwanted apps to access personal files on external media and potentially exfiltrate or modify that data.
Affected Systems
Apple’s macOS is vulnerable across multiple releases; the issue is mitigated in macOS Sequoia 15.4, macOS Sonoma 14.7.3, and macOS Ventura 13.7.3. Systems running any earlier macOS version are at risk, as applications may obtain elevated permissions to removable volumes without user approval.
Risk and Exploitability
The exploitability score is extremely low (EPSS < 1%) and the vulnerability is not listed in the CISA KEV catalog, suggesting limited active exploitation. However, the CVSS v.3.1 score of 9.8 indicates a high technical severity. Attackers can potentially trigger the flaw by installing a malicious or compromised application that leverages the elevated permissions, thus gaining access to data on USB sticks, SD cards, or other removable media.
OpenCVE Enrichment
EUVD