Impact
The vulnerability is a logic flaw, identified as CWE‑693, that was corrected with additional checks in a recent macOS update. The flaw permits an application to circumvent user-configured privacy preferences, potentially exposing or using sensitive data without explicit consent.
Affected Systems
Apple macOS versions older than macOS Sequoia 15.5, macOS Sonoma 14.7.6, and macOS Ventura 13.7.6 are susceptible to this flaw.
Risk and Exploitability
The CVSS score is 7.8, indicating a high risk to confidentiality because the app can read or access data beyond the user’s intent. The EPSS score of less than 1% shows that current exploitation activity is rare, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local or privileged application that requests elevated permissions, so the bug is most easily exploited when the attacker can run or install an application on the target machine.
OpenCVE Enrichment
EUVD