Impact
A file‑level permissions flaw in macOS, addressed by removing vulnerable code, allows an application to read protected user data that it should not be able to access. The weakness is categorised as information exposure and can lead to confidentiality loss if a malicious or compromised app is able to read or exfiltrate personal files or system data.
Affected Systems
Apple macOS versions prior to macOS 26.3 are vulnerable. The issue was fixed in macOS 26.3 and later releases.
Risk and Exploitability
The vulnerability has a moderate CVSS score of 5.5, and the EPSS indicates a very low probability of exploitation (<1 %). It is not listed in the CISA KEV catalog, implying no publicly known widespread attacks. Likely exploitation would involve a locally running application that can bypass sandbox restrictions, suggesting a local, privilege‑escalation style vector rather than a remote attack.
OpenCVE Enrichment