Impact
A permissions issue was identified that could allow an application to access sensitive user data. The vulnerability arises from insufficient restrictions, enabling unauthorized data exposure. The flaw is categorized as CWE-276: Incorrect Permissions, indicating a misconfiguration in how permissions are enforced.
Affected Systems
Apple macOS is affected. Vulnerable versions include any macOS iterations prior to the release of macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, and macOS Tahoe 26.2. The issue is addressed in the specified patches for each major release.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at present. It is not listed in CISA’s KEV catalog. Based on the description, the attack vector is most likely local, requiring the application to run with elevated or incorrect permissions. The risk is therefore moderate to high for systems running affected macOS versions where untrusted applications may obtain sensitive data.
OpenCVE Enrichment