Impact
This vulnerability arises from insufficient entitlement checks in the macOS operating system, allowing an application to access user‑sensitive data that it should not be authorized to read. The weakness is an Access Control flaw (CWE‑284), and an attacker could exploit it to compromise the confidentiality of protected information.
Affected Systems
Apple macOS is affected. The issue was fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, and macOS Tahoe 26.1, so any earlier or unpatched releases may remain vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity impact, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an application running on the device can exploit the missing entitlement checks, implying a local attack vector that does not require network access or elevated system privileges beyond the application's signed entitlement.
OpenCVE Enrichment