Impact
An authorization flaw in Apple macOS allows an installed application to capture Touch Bar content without proper entitlement checks, enabling unauthorized extraction of user interface information such as passwords or personal messages. This weakness is an access‑control issue (CWE‑862) that primarily threatens confidentiality by exposing sensitive data displayed on the Touch Bar.
Affected Systems
Apple macOS operating systems released prior to macOS Golden Gate 27, on machines equipped with a Touch Bar display. Users running these versions of macOS are vulnerable if an application that can run locally has the opportunity to execute on the system.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating moderate severity, and a very low EPSS score of less than 1 %, suggesting a low likelihood of exploitation. It is not listed in the CISA KEV catalog. Exploitation would likely require local execution of a malicious or compromised application, as the flaw does not provide a remote attack vector.
OpenCVE Enrichment