Impact
Apple has identified an access issue that was mitigated by adding additional sandbox restrictions. The flaw could allow a malicious or compromised application to read protected user data it normally could not access. This represents a moderate-level information disclosure vulnerability, classified under CWE-862 for improper privilege checks.
Affected Systems
The vulnerability applies to macOS versions prior to Sequoia 15.3. All earlier releases of macOS Sequoia are potentially affected as the issue was fixed in the 15.3 update.
Risk and Exploitability
The CVSS score of 5.5 denotes a moderate severity, and the EPSS score of <1% suggests a very low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local; a user who runs a malicious application, or obtains a compromised app on a device, could exploit the sandbox bypass to access sensitive data.
OpenCVE Enrichment
EUVD