Impact
A permissions flaw in macOS prevents the sandbox from adequately restricting when remote content is rendered in email previews. Because the “Block All Remote Content” setting may not apply consistently, an attacker can cause arbitrary web resources to be fetched without user consent, potentially leaking sensitive information or delivering malicious payloads via the mail preview mechanism.
Affected Systems
Apple macOS users on versions prior to Sequoia 15.4, Sonoma 14.7.5, or Ventura 13.7.5 are affected. The vulnerability has been remedied in those releases.
Risk and Exploitability
The CVSS score of 9.8 signals a high‑severity flaw, yet the EPSS score is under 1%, indicating a low current exploitation probability. The issue is not yet listed in the CISA KEV catalog. Attackers would likely target mail clients through crafted messages that trigger preview rendering; given the severity and the unrestricted permission nature, the remote content exposure could aid further attacks such as phishing or data exfiltration.
OpenCVE Enrichment
EUVD