Impact
The vulnerability allows a normal user to disable the Forcepoint One Endpoint SafariExtension, which is responsible for enforcing data loss prevention rules for Safari on macOS. Disabling the extension removes the active protection layer and enables the user to transmit or otherwise access enterprise data that would normally be blocked. The flaw is rooted in the lack of proper validation of the extension’s enabled status (CWE‑754).
Affected Systems
Forcepoint One Endpoint for macOS versions prior to v26.04.5758 are affected. The advisory does not explicitly state which macOS releases are supported, so that portion is inferred.
Risk and Exploitability
The CVSS score of 4.8 classifies the issue as moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The vulnerability allows a non‑admin user with local access to disable the SafariExtension. The inference that widespread exploitation is limited is based on the local nature of the attack, but this is not directly stated in the source.
OpenCVE Enrichment