Impact
A logic flaw in macOS was discovered, allowing an application to read sensitive user data that it should not have access to. The vulnerability is a logical flaw that does not rely on incorrect input handling but on inadequate checks, classified under CWE-284. The flaw could result in data disclosure for users of affected macOS installations, and the CVSS score of 5.5 indicates moderate severity.
Affected Systems
Any macOS system running a version prior to Sequoia 15.7, Sonoma 14.8, or Tahoe 26 is vulnerable. The fix was applied in those specific releases, so installing Sequoia 15.7 or later, Sonoma 14.8 or later, or Tahoe 26 or later removes the issue.
Risk and Exploitability
The CVSS score of 5.5 reflects medium impact, and the EPSS score of less than 1% shows very low probability of exploitation under current conditions. The flaw does not appear to be publicly exploited (not in KEV) and the attack path requires an application to be executed with the ability to access the affected data, most likely following local or privileged execution. The lack of an external exploit means the risk remains low, but the vulnerability still poses a data‑exposure threat.
OpenCVE Enrichment
EUVD