Impact
Apple’s macOS had not enforced sufficient checks to prevent a malicious application from accessing private data. The vulnerability can lead to the disclosure of sensitive user information, which is a moderate‑severity issue as reflected by the CVSS score of 5.5. It represents an information‑exposure weakness (CWE‑200).
Affected Systems
The flaw applies to all macOS releases older than macOS Sequoia 15.4 and macOS Sonoma 14.7.5. Systems running those older releases remain vulnerable until updated to the mentioned versions or later.
Risk and Exploitability
The EPSS score of less than 1% indicates very low current exploitation probability, and the flaw is not listed in the CISA KEV catalog. The attack vector is most likely local or through a privileged malicious application; an attacker would need to install or otherwise execute a compromised app to exploit the weakness. The impact is confined to information disclosure and does not enable code execution or remote compromise.
OpenCVE Enrichment
EUVD