Impact
This vulnerability, documented as CWE‑200, results from a missing or insufficient authorization check during sensitive data access on Apple macOS. An application bearing the required privileges could read protected user information that it should not be allowed to see. The exposure leads to loss of confidentiality, potentially revealing personal or confidential data.
Affected Systems
Apple macOS is affected. Versions prior to macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6 contain the flaw. Systems running earlier releases of these operating systems may be vulnerable if the issue persists in the kernel or system frameworks.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is under 1%, and it is not listed in the CISA KEV catalog, suggesting a low but not negligible likelihood of exploitation. Based on the description, the likely attack vector involves a local application that already runs on the user’s machine; this is inferred from the wording that an app may read sensitive data. Once accessed, the data could be exfiltrated by the malicious code.
OpenCVE Enrichment