Impact
An application can access sensitive user data due to a permissions issue on macOS. The flaw is a lack of proper restriction on data exposure, corresponding to CWE‑200 Non‑Authoritative Information Disclosure. This allows an app to read private data that should be protected, though it does not provide execution or privilege escalation.
Affected Systems
Apple macOS is affected. The issue is fixed in macOS Sequoia 15.7.3 and macOS Tahoe 26.2, so all earlier releases of Sequoia and Tahoe are vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1 % implies a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local, where a user installs or runs a malicious app that takes advantage of the permissions flaw to read private data.
OpenCVE Enrichment