Impact
An improper state‑management flaw in macOS allows a malicious or already‑installed application to read sensitive user data that it should not access. The vulnerability was corrected in macOS Golden Gate 27 and can lead to the exposure of private information without requiring elevated privileges.
Affected Systems
Apple macOS is affected, with the vulnerable versions being all releases prior to macOS Golden Gate 27.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that a widespread, automated exploitation campaign has not yet been observed. However, without a hard‑coded CVSS score, the risk remains uncertain, but the nature of the flaw indicates that local or remote applications could potentially exploit it if state information is incorrectly handled. The lack of an official workaround means that the only confirmed mitigation is upgrading to the patched macOS version.
OpenCVE Enrichment