Impact
The vulnerability arises from insufficient privacy controls that allow a local application to read user data it should not access. An affected app can access sensitive information, potentially exposing personal data. This flaw is an information disclosure flaw aligned with CWE‑200, which can compromise confidentiality.
Affected Systems
Apple macOS is affected, specifically the Sequoia and Sonoma lines running versions earlier than macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8. The issue impacts all releases prior to these patch versions.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The CVSS score of 5.5 denotes moderate severity, suggesting the potential impact is somewhat limited but non‑negligible. The likely attack vector is local, relying on an application that can read protected data; remote exploitation is not indicated. With no publicly known exploits and a low EPSS score, the risk remains limited, but upgrading is still advisable to mitigate potential information leakage.
OpenCVE Enrichment