Impact
A configuration issue in macOS permits an application to potentially deceive a user into copying sensitive information to the system pasteboard. This flaw allows the disclosure of data that a user did not explicitly intend to share. The weakness is classified as CWE‑359, indicating a sensitive data exposure vulnerability, and is reflected in a CVSS score of 4.4, which signifies moderate severity.
Affected Systems
The affected operating systems are Apple macOS releases prior to macOS Sequoia 15.7, macOS Sonoma 14.8, and macOS Tahoe 26. Versions released after these updates incorporate additional restrictions that mitigate the issue. The vendor specifies that the fix applies to the aforementioned release branches, but earlier builds remain susceptible.
Risk and Exploitability
The low EPSS score of less than 1 percent suggests that exploitation is unlikely to be widespread at this time. The vulnerability is not listed in CISA's KEV catalog, further indicating that there are no known widespread attacks leveraging this flaw. Given that the attack likely relies on social engineering—tricking a user into copying data—the vector is local and requires user interaction. The CVSS rating indicates a moderate impact but the overall risk to a system is limited unless an attacker can convincingly manipulate user behavior.
OpenCVE Enrichment
EUVD