Impact
A defect in macOS’s handling of sensitive information allows an application to read data that should have been obscured, resulting in inadvertent disclosure of private user data (CWE‑200).
Affected Systems
Apple macOS versions prior to Sequoia 15.4 are potentially impacted; the issue is fixed in Sequoia 15.4 and later releases.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, but the EPSS score of less than 1% suggests exploitation is unlikely at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to execute or otherwise manipulate a local application to access the exposed data. Based on the description, it is inferred that the attack vector is local and depends on third‑party application behavior.
OpenCVE Enrichment
EUVD