Impact
The vulnerability is a permissions issue at the operating system level that allows an application to read user data that should be protected, thereby enabling unauthorized disclosure of sensitive information within the user’s account. The weakness is classified as Improper Access Control (CWE‑284). The description indicates that the issue was addressed with additional restrictions, meaning the flaw allowed an app to access data beyond its intended scope.
Affected Systems
Apple macOS is affected. The vulnerability was fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, and macOS Tahoe 26. Versions of macOS prior to these releases, whether from the same or older series, remain vulnerable if they have not been updated to the fixed build.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, while the EPSS score of < 1% reflects a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local application running on macOS that can read protected user data without proper entitlement checks. An attacker could, therefore, exploit the flaw by installing a malicious or misconfigured app that requests excessive permissions to gain access to confidential files and information.
OpenCVE Enrichment
EUVD