Impact
The vulnerability is an information disclosure flaw that allows an application to read sensitive user data that it should not have access to. This issue is categorized as CWE‑200: Exposure of Sensitive Information to an Unauthorized Actor. The weakness is introduced by insufficient privacy controls inherent in the operating system, enabling an attacker to obtain confidential data through a malicious or compromised app.
Affected Systems
Apple’s macOS is affected, with the issue reported for versions prior to macOS Sequoia 15.5. The update to macOS Sequoia 15.5 includes the necessary fix. Earlier releases of macOS Sequoia and earlier macOS versions that have not applied the patch remain vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk, primarily affecting confidentiality. The EPSS score of less than 1% suggests a very low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious or compromised application that a user installs; such an app could read protected data without additional privileges. Because no additional authentication or privilege escalation is required, the condition to exploit the flaw is straightforward for a capable attacker.
OpenCVE Enrichment
EUVD