Impact
The vulnerability arises from missing entitlement checks in macOS, allowing an application to read or access sensitive user data that it should not be able to see. This results in a data disclosure scenario where privileges are improperly granted to software, potentially exposing personal information or system secrets.
Affected Systems
Apple macOS is affected; versions prior to macOS Sequoia 15.7, macOS Sonoma 14.8, and macOS Tahoe 26 are vulnerable. The issue was fixed in those releases, so environments running earlier builds could be impacted.
Risk and Exploitability
The CVSS score is 3.3, indicating a low severity; the EPSS score is below 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of exploitation. Based on the description, the likely attack vector is local, whereby an installed application can take advantage of the missing checks. No public exploit has been disclosed.
OpenCVE Enrichment
EUVD