Impact
A permissions issue was addressed by removing vulnerable code, allowing an application to access sensitive user data that it should not be able to read. The flaw enables data disclosure that could undermine user privacy and potentially lead to further compromise if the data is used for malicious purposes.
Affected Systems
Apple macOS products are affected. Systems running versions prior to macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, or macOS Tahoe 26.4 are vulnerable. The issue has been fixed in the quoted update releases.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests that exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local access to the machine and the ability to run or influence a third‑party application to leverage this flaw. Remote exploitation is not supported by the description.
OpenCVE Enrichment