Impact
This vulnerability is a permissions flaw that allows an application to supersede user-configured privacy preferences, enabling unauthorized access to sensitive data or resources that are normally protected. The flaw is considered a high severity issue, as it can undermine the confidentiality of user information by allowing software to read or use private data without explicit consent. The vulnerability is documented as a CWE-284 weakness in access control.
Affected Systems
Apple macOS versions prior to macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7 are affected. Users running any earlier releases of these operating systems are potentially vulnerable to the privacy preference bypass unless they have manually mitigated the issue through custom security settings.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, yet the EPSS score of less than 1% suggests that exploitation is currently unlikely but not impossible. The flaw has not been listed in the CISA KEV catalog, implying that no actively exploited variants are known. The attack vector is inferred to be local, relying on a user-installable application that can exploit the permission oversight once it is present on the system.
OpenCVE Enrichment
EUVD