Impact
An improper state‑management flaw in macOS allows malicious or already‑installed applications to read sensitive user data that should be protected. The vulnerability was addressed in macOS Golden Gate 27 and can lead to the exposure of private information. The description does not delineate whether privileged access is required to exploit the flaw.
Affected Systems
Apple macOS is affected, with the vulnerable versions being all releases prior to macOS Golden Gate 27.
Risk and Exploitability
The EPSS score is < 1% and the CVSS score of 5.5 indicate moderate risk and that the vulnerability is not widely exploited yet. The vulnerability is not listed in the CISA KEV catalog. The description does not specify the privilege level needed for exploitation, but improper state management could be leveraged by any application that can read state data. Accordingly, the likely attack vector is local or remote, depending on an attacker’s ability to run or influence applications on the affected system; this inference is based on the description.
OpenCVE Enrichment