Impact
The vulnerability arises from a permissions oversight that lets a shortcut read files normally off‑limits to the Shortcuts application. This could expose sensitive user data if a malicious shortcut is executed. The weakness is an instance of improper access control.
Affected Systems
Apple macOS is affected. Versions prior to macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, and macOS Tahoe 26.1 lack the fix and are therefore vulnerable.
Risk and Exploitability
The CVSS score of 6.2 indicates medium severity, while the EPSS score of less than 1 % shows exploitation is unlikely at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a local attacker delivering a malicious shortcut that a user runs; the description does not specify remote exploitation, so the threat is inferred to be local.
OpenCVE Enrichment