Impact
An input validation flaw identified as CWE-74 permits a malicious application to inject data that bypasses safeguards, enabling it to read or otherwise access sensitive user data on macOS. This vulnerability does not provide arbitrary code execution but can expose personal information or files that the user would normally be prevented from accessing.
Affected Systems
Apple macOS products, all releases prior to macOS Sequoia 15.6, are affected by this defect. The flaw was fixed in macOS Sequoia 15.6 through improved validation logic.
Risk and Exploitability
The CVSS score of 5.5 classifies this as a moderate severity issue. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, attackers could potentially embed malicious data in an application or via user input to gain unauthorized access to sensitive information, so the risk remains tangible for users running older OS versions.
OpenCVE Enrichment
EUVD