Impact
A local attacker may determine the legacy VNC password configured for Screen Sharing because the system lacked the necessary entitlement checks during the authentication process. This flaw permits the disclosure of credentials that were intended to be protected, potentially exposing the password to anyone with local access to the machine.
Affected Systems
Apple macOS devices running earlier than macOS Sequoia 15.7.8 or macOS Sonoma 14.8.8 are affected. The vulnerability applies to any release of these macOS families prior to the specified fix updates.
Risk and Exploitability
The CVSS score of 5.5 signals a medium severity vulnerability, and the EPSS score of <1% indicates a very low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. Because the flaw is local, an attacker needs local access or privileges to read the legacy VNC password; there is no known public exploit beyond this local disclosure scenario.
OpenCVE Enrichment