Impact
The vulnerability is a permissions issue in macOS that allows an application to access sensitive user data that it should not be able to reach. The lack of proper permission checks can enable data leakage, potentially compromising confidentiality of user information. This weakness is identified as CWE-359, indicating insufficient authentication or authorization checks.
Affected Systems
Apple macOS versions affected include macOS Sequoia, macOS Sonoma, and macOS Tahoe. Specifically, installations that have not been updated to macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, or macOS Tahoe 26.1 remain vulnerable.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate severity. The EPSS score is less than 1 %, indicating a low probability of exploitation at present. The vulnerability is not cataloged in CISA KEV. While the official description does not state the precise attack vector, it is inferred that exploitation could occur locally by a user or malware capable of running the affected application. No publicly available exploitation references are provided.
OpenCVE Enrichment