Impact
The vulnerability stems from improper state management in macOS, enabling a malicious application to read arbitrary files on the device. This can lead to disclosure of sensitive data stored on user or system volumes, potentially providing a foothold for further attacks. The flaw is an instance of information‑disclosure weakness under CWE‑200.
Affected Systems
The fix is included in macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5. Any macOS installation older than those versions—including Sequoia 15.3, Sonoma 14.6, Ventura 13.6 and earlier—is vulnerable. The issue has been declared for all Apple macOS products.
Risk and Exploitability
The CVSS score of 9.8 signals a severe risk, while the EPSS score of less than 1% indicates a low likelihood of exploitation as of now. The vulnerability is not present in the CISA KEV catalog. The primary attack vector is likely a local malicious application that takes advantage of the state‑management flaw to read protected files. No remote exploitation or network access is implied directly in the description.
OpenCVE Enrichment
EUVD