Impact
The vulnerability is an authorization flaw that enables an application to read sensitive user data it should not be able to access. It originates from insufficient state management in the operating system, classified as CWE‑200. The failure permits private information to be disclosed by third‑party applications, violating user privacy and potentially exposing personally identifying data.
Affected Systems
Apple macOS Tahoe and Apple watchOS are affected on any release prior to 26.6. The flaw is fixed in macOS Tahoe 26.6 and watchOS 26.6.
Risk and Exploitability
The flaw requires local, device‑based access and is limited to applications installed on the affected systems. No public exploit is known. The CVSS score of 5.5 indicates moderate risk, while an EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Consequently, the risk is primarily local and can be mitigated by promptly applying the available OS update.
OpenCVE Enrichment