Impact
The vulnerability stems from insufficient authorization checks in macOS, allowing applications to read user data without the necessary permissions. Classified as CWE‑285 (Improper Authorization), the flaw can enable unwanted disclosure of sensitive information.
Affected Systems
Apple macOS versions earlier than Sequoia 15.7.5, Sonoma 14.8.5, and Tahoe 26.4 are impacted.
Risk and Exploitability
With a CVSS score of 5.3, the issue has moderate severity, while an EPSS score below 1 % indicates a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers are expected to leverage local execution of an application that bypasses the missing checks, potentially exposing confidential data. The likely attack vector is local, inferred from the description of unauthorized data access via insufficient checks.
OpenCVE Enrichment