Impact
The vulnerability is an out‑of‑bounds read that can expose sensitive user data. This weakness is a classic CWE‑125 error, allowing an application to read memory outside intended bounds and potentially retrieve private information. The primary impact is information disclosure, compromising confidentiality of user data without affecting integrity or availability.
Affected Systems
Apple’s macOS is impacted. The issue is fixed starting with macOS Sequoia 15.7, macOS Sonoma 14.8, and macOS Tahoe 26. Versions prior to these are vulnerable. The vulnerability exists in the operating system kernel and any application that interacts with the affected subsystem.
Risk and Exploitability
The CVSS score of 5.5 places the vulnerability in the medium severity range, while the EPSS score of <1% indicates a very low current exploitation probability. It is not listed in the CISA KEV catalog, suggesting limited known exploitation. Based on the description, the likely attack vector is a local application or process that can trigger the out‑of‑bounds read; remote exploitation is unlikely without further techniques.
OpenCVE Enrichment
EUVD