Impact
This vulnerability arises from missing entitlement checks, allowing an application to access protected user data that it should not be able to see. The flaw is a classic example of missing authorization (CWE‑862) and could lead to the disclosure of confidential information. The impact is limited to confidentiality, as the attacker gains read access to data rather than full system control.
Affected Systems
Apple macOS systems are affected across multiple releases. Versions prior to macOS Sequoia 15.7, macOS Sonoma 14.8, and macOS Tahoe 26 do not contain the fix, whereas those releases and later include the additional entitlement checks that mitigate the issue.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and an EPSS score of less than 1% suggests a low probability of exploitation in the wild at present. It is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector involves a local application that is inadvertently granted the wrong permissions; an attacker would need to supply or influence a malicious or compromised application to take advantage of the entitlement gap.
OpenCVE Enrichment
EUVD