Impact
An access issue was addressed with improved access restrictions, and is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6, and macOS Tahoe 26.7. The vulnerability allows an app to access user‑sensitive data beyond its intended scope. It does not enable arbitrary code execution but does compromise data confidentiality.
Affected Systems
Apple macOS systems running versions prior to Sonoma 14.8.8, Tahoe 26.6, or Tahoe 26.7 remain vulnerable. The issue is fixed in those releases, so any machine still on an earlier patch level is at risk. The description specifically references macOS as the impacted product.
Risk and Exploitability
The flaw carries a CVSS score of 8.6, indicating a high severity, and an EPSS score of less than 1% suggesting limited exploitation probability in the wild. The vulnerability falls under the access control family (CWE‑284). Attackers can gain unauthorized access to user‑sensitive data by exploiting insufficient access restrictions in macOS, as documented in official advisories. Because the flaw does not allow remote code execution, its impact is confined to data confidentiality, but the high severity and lack of KEV listing mean it remains a significant risk for devices that remain on older macOS releases.
OpenCVE Enrichment