Impact
The vulnerability allows an attacker with physical access to a locked macOS device to view sensitive user information. The flaw is mitigated by improved checks and is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.5. The primary impact is the disclosure of confidential data, potentially compromising personal files and credentials.
Affected Systems
Apple macOS devices prior to macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.5 are affected. The issue has been addressed in those versions and later releases.
Risk and Exploitability
The CVSS score is 4.6, indicating a moderate severity. The EPSS score is less than 1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires physical proximity to a locked device; no network access is needed. Attackers who gain such access can read data without authentication, posing a risk primarily to users with less strict physical security.
OpenCVE Enrichment