Impact
A logic defect in macOS allows a malicious application to access private data that it should not be able to reach. The flaw is a software logic oversight that was corrected with additional checks in newer releases. An attacker could exploit this weakness to read or retrieve sensitive information kept by the operating system.
Affected Systems
Apple macOS versions that are older than Sequoia 15.7, Sonoma 14.8, and Tahoe 26 are affected. The issue was fixed in those releases, so any system running a pre‑patch version of the compatible macOS editions is vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity flaw. The EPSS score of less than 1% suggests a low probability of exploitation. This vulnerability is not listed in the CISA KEV catalog, implying that no widespread exploitation has been documented. The attack vector is most likely a malicious app installed on the user’s device, so local privilege or application-level compromise is required. The overall risk remains moderate, but remediation is recommended to prevent possible unauthorized data access.
OpenCVE Enrichment
EUVD