Impact
A permissions issue, addressed by removing the vulnerable code, allows an application to read protected user data that it should not be able to access. The weakness is categorized as information exposure and can lead to confidentiality loss if a malicious or compromised app can read or exfiltrate personal files or system data. The issue is fixed in macOS Sequoia 15.7.4 and macOS Tahoe 26.3.
Affected Systems
Apple macOS versions prior to macOS Sequoia 15.7.4 or macOS Tahoe 26.3 are vulnerable.
Risk and Exploitability
Based on the description, it is inferred that an attacker would need to run a malicious or compromised application locally with elevated privileges or bypass sandbox restrictions to exploit the issue. The CVSS score of 5.5 indicates moderate risk, while the EPSS score of less than 1 % reflects a very low probability of exploitation. It is not listed in the CISA KEV catalog, indicating no publicly known widespread attacks.
OpenCVE Enrichment