Impact
The vulnerability is caused by insufficient verification checks in macOS that allow a software application to read protected user data. This weakness, classified as CWE‑200, permits the application to access files and documents that are normally restricted, leading to unauthorized disclosure of personal information.
Affected Systems
macOS is affected. Any macOS installation prior to the release of Sequoia 15.4, which implements the fix, may be vulnerable. The description does not list individual version ranges beyond this release date, so all earlier macOS versions lacking the update are potentially impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that the primary attack vector is local, requiring the ability to run a malicious or compromised application on the target system. Remote exploitation is not explicitly excluded but is not indicated by the available data.
OpenCVE Enrichment
EUVD