Impact
A logic flaw in macOS permitted an application to read a user's contacts without the proper permissions. The flaw was addressed with improved restrictions. The impact is that an unprivileged application could gain unintended access to personal contact data, potentially exposing phone numbers, email addresses, and other sensitive information. This weakness relates to improper access control (CWE‑1284).
Affected Systems
Apple macOS. Versions affected until the bug was fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, and macOS Ventura 13.7.3. Earlier releases prior to these versions remain vulnerable.
Risk and Exploitability
The CVSS score of 3.3 indicates a low severity, and the EPSS score of less than 1% signals a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. Likely exploit would involve a malicious app being installed on the local system, leveraging the logic issue to read contacts. No remote code path is indicated, and no active exploitation is reported.
OpenCVE Enrichment
EUVD