Impact
An application running on macOS could read sensitive user data before a recent security improvement was deployed. The flaw results in a data‑exposure weakness (CWE-200) that allows an app to access data it should not be able to see. The problem has been mitigated in recent releases of macOS, but prior versions could still allow unauthorized data access.
Affected Systems
Apple’s macOS operating system is affected, specifically any release before macOS Sequoia 15.6 or macOS Sonoma 14.7.7. Users with earlier versions of the operating system are at risk of having apps read confidential data they should not access.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely local or macOS app‑install related, and would require the attacker to install or run a compromised application on the affected system to read protected data.
OpenCVE Enrichment
EUVD