Impact
The vulnerability allows an application to access sensitive user data without proper protection, leading to information exposure. This flaw is classified as CWE-200 and can result in the accidental disclosure of private data, compromising the confidentiality of a user’s information.
Affected Systems
Apple’s macOS platform is affected, specifically versions prior to macOS Tahoe 26.3. The issue is not limited to a single product line, as any macOS installation that has not been upgraded to the latest 26.3 release is potentially vulnerable.
Risk and Exploitability
With a CVSS score of 5.5, the vulnerability falls into the medium severity range. The EPSS score is under 1%, indicating a low probability of exploitation at the time of analysis, and it is not listed in the CISA KEV catalog. Attackers would likely need local execution privileges or the ability to install or run an application, as the flaw permits a malicious or compromised app to read protected data. Because the weakness is informational, there is no known remote exploitation path.
OpenCVE Enrichment