Impact
A sandbox permission flaw lets an application bypass restrictions and read protected user data, exposing confidentiality and potentially allowing further unauthorized actions. The weakness is categorized as improper privilege management (CWE-276).
Affected Systems
Apple macOS versions prior to Sequoia 15.4, Sonoma 14.7.5, and Ventura 13.7.5 are affected. The vulnerability is resolved in the later releases listed above. No other vendors or products are impacted.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% points to a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed active exploitation. Likely attack requires local execution of a malicious or compromised application that can elevate its privileges within the sandbox. Because the flaw involves access to protected data, a user who installs or runs such software could inadvertently expose sensitive information.
OpenCVE Enrichment
EUVD