Impact
An application may read sensitive user data due to inadequate access checks, resulting in a breach of confidentiality. The weakness is an information exposure flaw (CWE‑200).
Affected Systems
Apple macOS users running versions older than macOS Tahoe 26.4 are potentially vulnerable; the issue was fixed in that release.
Risk and Exploitability
The vulnerability scores a medium CVSS score of 5.5 and has a low EPSS probability (< 1 %). It is not included in the CISA KEV catalog. An attacker would need a malicious or compromised application or a local user with sufficient privileges to benefit from the flaw, which is inferred from the description but not explicitly stated in the advisory.
OpenCVE Enrichment