Impact
A flaw in macOS cache handling allows an application to read protected user data that should not be accessible. The weakness is an information‑disclosure vulnerability, classified as CWE‑200, and it does not provide any ability to execute code or elevate privileges.
Affected Systems
Apple macOS installations prior to macOS Tahoe 26.2 are affected. The issue is resolved in Tahoe 26.2 and later, regardless of hardware or user configuration.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity, and the EPSS score of less than 1% suggests low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to run a malicious or untrusted application on the affected system; the flaw is effectively local and requires that the application have permission to access cache resources.
OpenCVE Enrichment