Impact
This flaw allowed applications to read the hostnames of new network connections, leaking sensitive information about network usage. It is an information‑exposure weakness identified by CWE‑200 and does not grant execution or modification privileges.
Affected Systems
Apple macOS systems running a version before Sequoia 15.5 are affected. The issue has been corrected by removing vulnerable code in Sequoia 15.5, so any macOS version older than 15.5 may be vulnerable.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity, while the EPSS score of less than 1 % and the lack of a KEV listing suggest a low likelihood of widespread exploitation. The vulnerability can be leveraged by a local application to observe hostnames as connections establish, which can reveal internal networking details without affecting confidentiality or integrity directly.
OpenCVE Enrichment
EUVD