Impact
A logic flaw in Apple macOS Tahoe permits an application to read sensitive user data it should not access, compromising data confidentiality. The vulnerability is classified as a logic failure (CWE‑497).
Affected Systems
Apple macOS (macOS Tahoe) versions prior to 26.1 are affected. The bug was fixed in the 26.1 release and later updates.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity, while an EPSS score of less than 1% suggests low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but an attacker could potentially abuse the logic error through a locally running or signed application to gain unauthorized data access.
OpenCVE Enrichment