Impact
A failure in macOS privacy controls allows an application to read user‑sensitive data that should be protected, resulting in a confidentiality breach. The flaw is classified as CWE‑200, which indicates an information disclosure weakness. No elevation of privileges is required; the affected application simply gains unauthorized access to data it normally cannot read.
Affected Systems
Apple’s macOS operating system is affected. All releases prior to macOS Sequoia 15.3 are vulnerable; the fix was introduced in Sequoia 15.3.
Risk and Exploitability
The CVSS score of 5.5 places the issue in the moderate severity range, while the EPSS value of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Likely, an attacker would need to supply a malicious or compromised application that the user installs locally to exploit the flaw, making it a local threat that can leak private data but not compromise system integrity or availability.
OpenCVE Enrichment
EUVD