Impact
This vulnerability arises from improper access control due to insufficient entitlement enforcement. The weakness, classified as CWE‑284, allows an application to read user‑sensitive information that it should not access. The issue was fixed in macOS Tahoe 26 through improved credential handling.
Affected Systems
Apple macOS systems, including all releases earlier than macOS Tahoe 26. Users running versions prior to 26 are affected and may allow applications to access private data.
Risk and Exploitability
The vulnerability has a CVSS score of 5.5, indicating moderate severity, and an EPSS score of less than 1%, suggesting low exploitation probability. It is not listed in CISA KEV. The likely attack vector is a local application executing on the user’s machine; an attacker would need to provide or trick the user into installing a malicious or overly privileged app.
OpenCVE Enrichment
EUVD