Impact
An authorization issue was addressed with improved state management. The vulnerability, identified as CWE-285, allows an app to access sensitive user data that it should not be able to read. The flaw arises from insufficient authorization checks, enabling an application to bypass normal protection mechanisms to retrieve data within the user’s environment.
Affected Systems
Apple macOS versions prior to the recent security updates are affected. Specifically, macOS Sequoia versions earlier than 15.7.4 and macOS Sonoma versions earlier than 14.8.4 are vulnerable to this authorization bypass. These systems lack the patched state management required to enforce proper access controls.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity. The EPSS score of less than 1% shows that documented exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. Likely, exploitation would involve a local or sideloaded application that can take advantage of the insecure authorization logic to read protected data. Although the risk is not high, any compromise of personal data can be costly to users and organizations.
OpenCVE Enrichment