Impact
The vulnerability is a permissions flaw that permits an application to read protected user data. It is a local privilege issue that could allow attackers to retrieve sensitive information without the user’s explicit consent. The flaw is identified as CWE-284, reflecting an improper authorization weakness.
Affected Systems
Apple’s macOS operating system is impacted, specifically versions before macOS "Tahoe" 26.1. The problem was addressed in macOS 26.1, so systems running earlier releases are vulnerable. Users on devices with older macOS versions may still be exposed.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. EPSS is less than 1%, suggesting low exploitation probability in the wild, and the vulnerability does not appear in the CISA KEV catalog. The likely attack path involves a local or user‑installed application taking advantage of insufficiently checked permissions. Because the flaw allows reading protected user files, its impact is primarily data confidentiality loss rather than system compromise.
OpenCVE Enrichment