Impact
An application can read private information that should have been omitted from system log entries, leading to unintended data exposure. The weakness is classified as CWE-284, improper access control, and compromises the confidentiality of user data.
Affected Systems
Apple macOS versions before Sequoia 15.7.2, Sonoma 14.8.2 and Tahoe 26.1 are susceptible, while those released with the corresponding updates are not. The flaw does not affect other operating systems.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, and the EPSS score of less than 1 % shows a very low likelihood of exploitation. No public exploits or CISA KEV listing exist. The description does not state an attack vector, but it is inferred that an application with the ability to write or read log files may be able to trigger the flaw, implying that local or app‑based exploitation is the plausible path.
OpenCVE Enrichment