Impact
A logic flaw was discovered in state management on macOS that can allow an application to obtain access to protected user data that it should not see. The flaw stems from incorrect handling of a state transition and does not result in a crash or denial of service, but it can be leveraged to read confidential information stored on the system.
Affected Systems
Apple macOS versions affected are macOS Golden Gate (v27), Sequoia (v15.8) and Tahoe (v26.7). These are the only releases where the issue was identified and patched.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.5 indicates a medium severity impact for allowing an app to read privileged data. The attack vector would require the attacker to run or install an application that can exploit the state management logic; thus it is likely a local or privileged threat model. Due to the lack of a publicly known exploit, the current risk is considered moderate pending the availability of a compound exploit.
OpenCVE Enrichment