Impact
A privacy issue within macOS allows an application to access sensitive user information that was previously protected by moving data into a more secure location. The flaw is a form of improper access control that could lead to confidential data being read by an unauthorized app. As a result, user privacy is directly impacted, with the potential for personal data to be disclosed to a malicious or unintended application.
Affected Systems
Apple macOS is the affected platform. The vulnerability existed in versions prior to macOS Tahoe 26.4, which includes the 26.4 update that fixed the issue. No other vendors or product versions were specified.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, further indicating limited real-world exploitation. Attackers would need to run or install an application that can leverage the broken access control to read protected data. The exploit requires no special user interaction beyond normal application use, but it is limited to platforms with the affected macOS versions. While the threat is moderate, remediation is prudent.
OpenCVE Enrichment