Impact
A permissions issue in Apple macOS allows applications to read sensitive location information more broadly than intended. The flaw was addressed by adding restrictions, and the fix is available in macOS Sequoia 15.4.
Affected Systems
Apple macOS Sequoia versions prior to 15.4 are affected. The vulnerability is resolved in macOS Sequoia 15.4 and later releases.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The flaw likely requires a local application to access location data beyond its intended scope. There is no mention of a network-based attack vector, and the vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
EUVD