Impact
A permissions issue that bypasses sandbox restrictions allows an application to access user-sensitive data, classified as CWE-359. The vulnerability can lead to the disclosure of confidential information stored on the device. The severity of the flaw is reflected by a CVSS score of 7.5, indicating high potential impact on confidentiality and integrity when exploited.
Affected Systems
Apple macOS is affected, specifically all releases prior to Sequoia 15.7.2, Sonoma 14.8.2, or Tahoe 26.1, where the sandbox restrictions were not yet updated. Users running earlier macOS versions may be able to run malicious applications that acquire restricted data.
Risk and Exploitability
The risk is moderate to high with a CVSS of 7.5, but the EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local: an attacker must install or run a malicious application that takes advantage of the weakened sandbox permissions. Without the patch, the bug can expose private data to an application that would normally be barred by sandbox controls.
OpenCVE Enrichment