Impact
A flaw in macOS allows an application to bypass normal access controls and read private user information. The weakness arises from insufficient validation checks during a sensitive data access operation, enabling the offending app to acquire data it should not have permission to see. The impact is primarily a confidentiality breach, with an attacker gaining unauthorized visibility into user content.
Affected Systems
The vulnerability affects Apple macOS systems. It has been addressed in macOS Tahoe version 26.1; earlier releases of macOS 26 are therefore susceptible.
Risk and Exploitability
The CVSS score of 5.5 categorises the issue as moderate severity, while the EPSS score of less than 1% suggests the likelihood of exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would likely require a user to install or run a malicious or compromised application on the affected Mac, and the attacker would obtain sensitive data that the operating system should protect.
OpenCVE Enrichment