Impact
The vulnerability involves a privacy flaw where a sandboxed process can bypass macOS sandbox restrictions. It was addressed by removing the vulnerable code in Sequoia 15.6 and is classified as CWE-311, meaning sensitive data was handled without proper protection. Based on the description, it is inferred that an attacker controlling a sandboxed application could read or modify data that should be confined within the sandbox, potentially exposing confidential information.
Affected Systems
Apple macOS systems running versions prior to Sequoia 15.6 are potentially affected. The CVE statement fixes the issue in Sequoia 15.6, implying that earlier releases still contain the code that may allow sandbox circumvention.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the description does not mention remote exploitation, it is inferred that the threat requires a sandboxed application to be run locally; remote attack is unlikely. The overall risk remains low to moderate.
OpenCVE Enrichment
EUVD