Impact
A race condition in macOS allows an application to bypass the system’s privacy preferences, potentially enabling the app to access data that should be locked behind user consent. The flaw was mitigated by adding validation checks but the race remains in versions prior to macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5.
Affected Systems
Apple macOS deployments running versions older than Sequoia 15.4, Sonoma 14.7.5, or Ventura 13.7.5 are vulnerable, as they lack the fix that resolves the race condition.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity level, while the EPSS score of less than 1% suggests that widespread exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, further limiting known attacks. Based on the nature of a race condition, the likely attack vector is a local or privileged application that manipulates timing to gain premature access to privacy-protected data, although the description does not explicitly confirm this vector.
OpenCVE Enrichment
EUVD