Impact
A logic flaw involving restricted access controls has been identified in macOS. The issue allows a local application to gain read access to content and other sensitive data it should not ordinarily see. The vulnerability stems from a flaw in how the system enforces user‑level permissions, enabling an application to bypass those checks and obtain confidential information.
Affected Systems
Apple macOS systems running versions prior to macOS Sequoia 15.6, macOS Sonoma 14.7.7, or macOS Ventura 13.7.7 are affected. The fix was delivered in those releases; any earlier macOS build remains vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score is below 1%, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring the attacker to run a malicious or compromised application on the target system. Given the weakness in access control (CWE‑284), exploitation would result in privileged read access to personal data rather than remote code execution or denial of service.
OpenCVE Enrichment