Impact
An authorization issue was addressed with improved state management. An app may be able to access sensitive user data, directly threatening confidentiality by exposing private information to unauthorized parties without requiring elevated privileges. Based on the description, it is inferred that the flaw allows an application to bypass normal authorization controls and read data that should otherwise be protected.
Affected Systems
Apple macOS systems running versions prior to the security update that introduced improved state management are vulnerable. This includes all builds of macOS that have not yet received the patches included in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.3. Users of older releases or those that have not applied these updates should be considered at risk.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity. The EPSS score of <1% suggests that exploitation is currently unlikely, and KEV indicates it is not listed. Based on the description, it is inferred that the likely attack vector is a software-based exploit delivered by a malicious or compromised application that manipulates state management. The risk is moderate, and timely remediation is recommended.
OpenCVE Enrichment