Description
This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability, documented as CWE‑200, results from a missing or insufficient authorization check during sensitive data access on Apple macOS. An application bearing the required privileges could read protected user information that it should not be allowed to see. The exposure leads to loss of confidentiality, potentially revealing personal or confidential data.

Affected Systems

Apple macOS is affected. Versions prior to macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6 contain the flaw. Systems running earlier releases of these operating systems may be vulnerable if the issue persists in the kernel or system frameworks.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. The EPSS score is under 1%, and it is not listed in the CISA KEV catalog, suggesting a low but not negligible likelihood of exploitation. Based on the description, the likely attack vector involves a local application that already runs on the user’s machine; this is inferred from the wording that an app may read sensitive data. Once accessed, the data could be exfiltrated by the malicious code.

Generated by OpenCVE AI on August 4, 2026 at 23:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade your macOS installation to the patched releases (macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, or macOS Tahoe 26.6).
  • Revoke unnecessary application permissions that grant access to sensitive data.
  • Keep all third‑party applications that access sensitive data up to date and verify their permissions are strictly required.

Generated by OpenCVE AI on August 4, 2026 at 23:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Sensitive Data Exposure via Improper Authorization Check in macOS

Mon, 03 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title macOS Vulnerability Allowing Unauthorized Access to Sensitive User Data
Weaknesses CWE-284

Thu, 30 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title macOS Vulnerability Allowing Unauthorized Access to Sensitive User Data
Weaknesses CWE-284

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:26:54.028Z

Reserved: 2026-05-01T22:46:27.819Z

Link: CVE-2026-43782

cve-icon Vulnrichment

Updated: 2026-07-28T14:26:49.137Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:02.600

Modified: 2026-07-28T19:47:47.660

Link: CVE-2026-43782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:45:02Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor