Impact
This vulnerability results from insufficient data protection in macOS, allowing an application to read sensitive user data that it should not access. Classified as CWE‑200, the flaw can lead to the disclosure of personal or confidential information. The description does not indicate any ability for code execution or privilege escalation; the impact is solely the loss of data confidentiality.
Affected Systems
Apple’s macOS operating system is affected, encompassing all releases up to and including macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, and macOS Tahoe 26.1. The fix is incorporated in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, and macOS Tahoe 26.2. Devices running earlier versions remain vulnerable.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need a malicious or compromised application present on the system to leverage the flaw. The likely attack vector is local, relying on an application’s unauthorized access to protected data, which moderates the overall risk in a protected environment.
OpenCVE Enrichment