Impact
A logic issue in macOS could allow an application to read sensitive user data. The flaw, identified as CWE-200, involves the exposure of information that should remain confidential. Based on the description, it is inferred that the attack vector may involve a malicious application exploiting the logic error.
Affected Systems
Apple’s macOS is impacted, specifically versions prior to the releases that contain the fix—macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.2. Users on older builds are susceptible to the flaw.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, while an EPSS of less than 1% signals a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector may involve a malicious application delivering the logic error, but this is inferred, and the threat is most pronounced for environments that allow installation of unverified software.
OpenCVE Enrichment