Impact
This vulnerability is a path handling issue in macOS that permits an application to resolve file paths leading to user‑sensitive data. The flaw corresponds to CWE‑22 and can result in a confidentiality breach if an app accesses files it should not normally read. The vulnerability does not grant execution privileges or system takeover, but it enables read access to protected resources.
Affected Systems
Apple macOS is affected, specifically versions earlier than macOS Sonoma 14.8.4 and macOS Tahoe 26.2. Any system running these revisions that allows third‑party applications is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.5 rates the vulnerability as moderate, while the EPSS score of less than 1% indicates a very low probability that it will be exploited in the wild. The issue is not listed in the CISA KEV catalog, implying no known active exploitation. The likely attack vector is a local or remote application that can provide or manipulate file paths, but the description does not confirm an active exploit. Therefore, the risk is moderate to low and mainly relevant to environments that require strict data protection.
OpenCVE Enrichment