Impact
The vulnerability is an access issue tied to insufficient sandbox restrictions that could allow a malicious or misconfigured application to read or manipulate sensitive user data. This weakness is categorized as Access Control (CWE-284) and is rated with a CVSS score of 5.5, indicating moderate risk to data confidentiality.
Affected Systems
It affects Apple macOS Tahoe 26 and any earlier versions running unpatched. The fix is included in macOS Tahoe 26, so systems on that OS or older are vulnerable.
Risk and Exploitability
The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, implying a low likelihood of exploitation. However, because the issue involves bypassing sandbox controls, a local attacker or a user with the ability to run applications could potentially exploit it to access sensitive information. The risk is higher in environments where personal data is stored or processed.
OpenCVE Enrichment
EUVD