Description
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.
Published: 2026-03-25
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Apply Patch
AI Analysis

Impact

An authorization flaw in macOS allows an application to read sensitive user data that it should not have access to. The vulnerability arises from insufficient state management that can be exploited by any app running on the system. This can lead to unauthorized disclosure of confidential information, violating both confidentiality and integrity.

Affected Systems

Apple macOS is affected. The issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4. All prior releases that have not applied the latest security update are potentially vulnerable. The vulnerability impacts devices running those macOS versions where the state management enforcement is not in place.

Risk and Exploitability

The CVSS score is 5.5, indicating medium severity, and the EPSS score is below 1%, suggesting a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Because the flaw permits an application to read sensitive data, a local or application‑level attacker could potentially exploit the vulnerability by installing a malicious app or by using a trusted app with elevated privileges. The attack vector is inferred to be application‑based within the local system context. The overall risk is moderate, but applying the patch reduces the risk to zero.

Generated by OpenCVE AI on March 27, 2026 at 21:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update macOS to the latest available security release (e.g., Sequoia 15.7.5, Sonoma 14.8.5, or Tahoe 26.4).
  • If an immediate update is not possible, monitor for and restrict any unauthorized applications that may attempt to read sensitive data.
  • Check Apple support or security advisories regularly for further updates or guidance.

Generated by OpenCVE AI on March 27, 2026 at 21:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 28 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
Title Authorization Flaw Allowing Unprivileged App Access to Sensitive User Data
Weaknesses CWE-284

Fri, 27 Mar 2026 09:30:00 +0000

Type Values Removed Values Added
Title Authorization Flaw Allowing Unprivileged App Access to Sensitive User Data
Weaknesses CWE-284

Thu, 26 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Thu, 26 Mar 2026 12:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Allows Sensitive Data Access in macOS
Weaknesses CWE-200
CWE-285

Wed, 25 Mar 2026 22:00:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Allows Sensitive Data Access in macOS
Weaknesses CWE-200
CWE-285

Wed, 25 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Wed, 25 Mar 2026 01:00:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:11:16.491Z

Reserved: 2026-03-03T16:36:03.968Z

Link: CVE-2026-28831

cve-icon Vulnrichment

Updated: 2026-03-27T19:44:55.986Z

cve-icon NVD

Status : Modified

Published: 2026-03-25T01:17:08.187

Modified: 2026-03-27T20:16:26.593

Link: CVE-2026-28831

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-29T20:28:37Z

Weaknesses