Impact
An application may be able to access protected user data because sensitive information was not properly separated. The consequence is a confidentiality breach whereby private data could be read by an unintended third party. The weakness corresponds to information exposure as identified by CWE-200.
Affected Systems
Apple macOS is affected. The issue remains in versions prior to Sonoma 14.8 and Tahoe 26. Users running those earlier releases have the potential to be impacted.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity. The EPSS score of less than 1% suggests that the likelihood of exploitation is low at present, and the vulnerability is not listed in the CISA KEV catalog. Because the description does not detail an active exploit, the attack vector is inferred to be a local or application‑based attack where a malicious or compromised app could read protected data. Although exploitation probability is low, the impact to privacy warrants remediation.
OpenCVE Enrichment
EUVD