Impact
A race condition in macOS (CWE-362) allows an application to read user‑sensitive data that should not be available to it. The vulnerability was remedied by adding additional validation checks. Based on the description, it is inferred that before the fix, an app that could coordinate timed operations might trigger the race to obtain protected information.
Affected Systems
Apple macOS builds older than macOS Sequoia 15.4, macOS Sonoma 14.7.5, or macOS Ventura 13.7.5 are impacted. Systems running those or earlier releases are susceptible.
Risk and Exploitability
The CVSS score of 4.7 indicates a moderate severity and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local or application‑level exploitation where a malicious app coordinates timed operations to trigger the race condition, thereby reading data that normally requires higher privileges.
OpenCVE Enrichment
EUVD