Impact
The CVE describes a logic issue in macOS that is mitigated by improved validation. The flaw allows an application to access user-sensitive data, representing information exposure (CWE-200) and improper authorization (CWE-285). The issue originates from insufficient validation of user context. No details are provided about the exact mechanics or vectors of exploitation.
Affected Systems
Apple’s macOS operating system is affected. Systems running any major release older than Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6 lack the fix and remain vulnerable. Updating to those or later releases resolves the issue.
Risk and Exploitability
The CVSS score of 5.5 classifies the flaw as moderate severity. EPSS indicates a less than 1 % likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV. No explicit attack vector is disclosed in the CVE description, so the exploitation scenario is not detailed. The impact is limited to user-sensitive data that the app can access within the user’s context.
OpenCVE Enrichment