Impact
An authorization flaw exists that could allow a malicious application to read sensitive user information on macOS. The vulnerability is an access control weakness (CWE‑284) resulting in a potential breach of confidentiality.
Affected Systems
The problem exists in macOS versions released before Sequoia 15.7.5, Sonoma 14.8.5, and Tahoe 26.4. Systems running those or earlier versions are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% points to a low probability of exploitation. The CVE is not listed in the CISA KEV catalog. Attackers would likely need local access to run a malicious application, so the attack vector is inferred as local execution. The impact remains limited to data breach, but the overall risk is considered moderate to low.
OpenCVE Enrichment