Impact
A permissions issue allowed an application to read files outside its sandbox, potentially exposing sensitive data to unauthorized binaries. The flaw is an improper access control abuse (CWE‑284) that could enable a malicious or compromised app to access files it should not see, thereby threatening user confidentiality and possibly violating privacy constraints.
Affected Systems
Apple macOS is affected. Versions prior to macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7 are vulnerable. The issue was fixed in those releases.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1 % suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves deploying a malicious app or manipulating an existing app on the user’s Mac to exploit the sandbox bypass, making the threat primarily local to the system where the app is executed.
OpenCVE Enrichment
EUVD