Impact
The flaw is a logic issue that was corrected with improved validation. A malicious application could exploit this oversight to read or access sensitive user data that should be protected. The vulnerability represents a data privacy breach, allowing an attacker to obtain confidential information without proper authorization.
Affected Systems
The affected product is Apple macOS. The fix is included in macOS Sequoia 15.7, macOS Sonoma 14.8, and macOS Tahoe 26. Therefore, any macOS installation running a version earlier than those is susceptible to this vulnerability.
Risk and Exploitability
The EPSS score is not available, and the CVE is not listed in the CISA KEV catalog, which suggests it has not yet been widely exploited in the wild. However, the underlying weakness allows a local malicious app to bypass validation checks, implying that the attacker could certify themselves as a trusted application or spoof user credentials to access data. While the precise attack vector is not explicitly documented, it is inferred that execution of a malicious macOS application on the target machine would suffice. The consequence is data exposure, which could be of moderate severity depending on the sensitivity of the accessed information. The CVSS score is 5.5, indicating moderate severity.
OpenCVE Enrichment