Impact
The vulnerability involves improper handling of caches that can expose deleted notes. An attacker who has physical access to the device could read data that was previously thought to be removed, compromising user privacy. The weakness corresponds to CWE-524, where sensitive data is not adequately protected after deletion.
Affected Systems
Apple macOS operating systems are impacted. The issue is fixed in the following releases: macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.2. All earlier versions of these OS code names may still be vulnerable.
Risk and Exploitability
The CVSS score is 2.4, indicating a low severity, and the EPSS score is less than 1%, suggesting a very small chance of exploitation. The vulnerability is not listed in CISA KEV. Likely exploitation requires physical access, which limits the practical threat, yet the privacy impact remains significant for sensitive notes.
OpenCVE Enrichment