Impact
An macOS application may acquire sensitive user data that should be protected, leading to disclosure of confidential information. This vulnerability is characterized by insufficient privacy controls that allow an app to read data beyond its intended scope. The weakness aligns with the class of information exposure flaws, which can compromise confidentiality.
Affected Systems
Apple macOS is affected, specifically the Sequoia and Sonoma lines running versions earlier than macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8. The issue impacts all releases prior to these patch versions.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The CVSS score of 5.5 denotes moderate severity, suggesting the potential impact is somewhat limited but non‑negligible. The likely attack vector is local, relying on an application that can read protected data; remote exploitation is not indicated. With no publicly known exploits and a low EPSS score, the risk remains limited, but upgrading is still advisable to mitigate potential information leakage.
OpenCVE Enrichment