Impact
A path handling flaw allows a sandboxed application to read files outside its protected area. The vulnerability results in unintended disclosure of data that the application should not have access to, potentially exposing sensitive system or user files. It is identified as CWE‑125, an out‑of‑bounds read weakness.
Affected Systems
Apple macOS is affected. The flaw exists in all releases of macOS Sequoia earlier than 15.3, Sonoma earlier than 14.7.3, and Ventura earlier than 13.7.3. Updating to any of these or later patched releases removes the vulnerability.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, and the EPSS score of less than 1% implies a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local execution of a malicious app or to manipulate an existing sandboxed app to gain the ability to read arbitrary files; remote exploitation is unlikely based on the provided information.
OpenCVE Enrichment
EUVD