Impact
A race condition was identified that allows an application to access sensitive user data without proper validation. The flaw occurs when concurrent processes manipulate shared data, potentially enabling a malicious app to read or modify information it should not have access to. The vulnerability can lead to confidentiality violations, allowing attackers to gain private data from the device.
Affected Systems
Apple macOS (Sequoia, Sonoma, Tahoe) and Apple tvOS are affected. The issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, and tvOS 26.6. Devices running earlier releases are susceptible.
Risk and Exploitability
The CVSS score is 4.7, and EPSS score is <1% (about 0.00094). The vulnerability is not listed in the CISA KEV catalog. The race condition likely requires a malicious or compromised application to be installed or executed on the device, indicating a local attack vector. Detection and exploitation would depend on the ability to trigger the race condition before validation is enforced.
OpenCVE Enrichment