Impact
Apple macOS handles environment variables without adequate validation. The flaw allows an application to read or modify sensitive user data through these variables, embodying a classic insecure input validation weakness (CWE‑20). The consequences are limited to confidentiality loss of data stored in environment variables but can be leveraged by a malicious app to gain unintended access to that data.
Affected Systems
The vulnerability affects Apple macOS in the following releases: macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7. Other macOS versions not listed are assumed unaffected without explicit statements.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity, while the EPSS score of <1% shows a low likelihood of exploitation today, and the vulnerability is not listed in CISA KEV. The likely attack vector is local, requiring a malicious application running on the user’s machine to set or read the compromised environment variables.
OpenCVE Enrichment
EUVD