Impact
A flaw in macOS permission enforcement lets an application bypass checks and access user data, potentially exposing sensitive information. This weakness arises from improper authorization handling, classified as CWE-863. The impact is the unauthorized acquisition of data that could be confidential or private.
Affected Systems
Apple macOS installations prior to the release of macOS Tahoe 26 are vulnerable. The issue was corrected in that version, so any macOS version older than macOS Tahoe 26 is at risk.
Risk and Exploitability
The CVSS score of 4 indicates a low severity, and the EPSS score of less than 1% suggests that real-world exploitation is unlikely. The vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is a local application that the user installs or runs, so the attacker would need to convince a user to run malicious code. Because only local code execution is required, no network exposure is necessary, and patching mitigates the risk.
OpenCVE Enrichment
EUVD