Impact
An authorization flaw due to improper state management allows a local application to gain unauthorized access to sensitive user data. The vulnerability, classified as privilege escalation, can lead to confidentiality breaches by enabling apps to read or modify data that should be restricted to the user.
Affected Systems
Apple’s macOS Tahoe platform is affected when running versions prior to the 26.3 update, which contains the fix for the state‑management issue. Users on earlier releases of macOS Tahoe therefore remain vulnerable.
Risk and Exploitability
The vulnerability carries a moderate CVSS score of 5.5 and an EPSS score below 1 %, indicating a low probability of exploitation. It is not listed in the CISA Known Exploited Vulnerabilities catalog. It is inferred that the most likely attack vector is local; based on the description, an application running with user privileges could exploit the weakened state controls to reach protected data. Because the flaw does not lead to remote code execution or system compromise, the overall risk is low but the impact on user privacy warrants remediation.
OpenCVE Enrichment