Impact
A vulnerability in macOS allowed a malicious application to read private data. The flaw was mitigated by removing the vulnerable code, but prior to that, an attacker could leverage an exposed interface to access sensitive information, resulting in disclosure of confidential data. This weakness aligns with CWE‑200, where information is revealed to an unauthorized party.
Affected Systems
The flaw affected Apple macOS versions prior to Sequoia 15.4, Sonoma 14.7.5, and Ventura 13.7.5. All releases newer than these contain the fix.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a malicious local application that the user installs; based on the description, it is inferred that the attacker could exploit an exposed interface to read protected data.
OpenCVE Enrichment
EUVD