Impact
A permissions flaw allows an application to bypass the additional restriction controls and read protected user data that it should not be able to access. This results in unauthorized software being able to obtain sensitive personal information, thereby compromising the confidentiality of user files and settings.
Affected Systems
Apple macOS versions prior to macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.3 are affected. The issue was fixed in these releases, so any system running an earlier patch level is vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves a local or application‑level attack where a malicious or compromised app is given elevated privileges. No remote network exploitation is explicitly documented, so the risk profile centers on the presence of the vulnerable app on the system.
OpenCVE Enrichment