Impact
This vulnerability results from improper handling of symbolic links within macOS, allowing a local application to read or otherwise access data that is otherwise protected. The weakness can be exploited by any app that the user runs, and is categorized as a CWE-59 path traversal issue. While the CVSS base score of 3.3 reflects a low severity, the potential for privacy compromise makes it a concern for data‑sensitive environments.
Affected Systems
Apple macOS is affected, specifically versions released before macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, or macOS Tahoe 26.1. Users running earlier releases of these operating systems have the vulnerability in effect.
Risk and Exploitability
The EPSS value of less than 1% indicates a very low likelihood of exploitation in the wild, and the issue is not listed in CISA’s KEV catalog. The attack vector is inferred to be local, requiring a user to execute a malicious application that can manipulate symbolic links. The low CVSS score reflects the limited impact, but the confidentiality risk remains for user data that could be exposed by the affected app.
OpenCVE Enrichment