Impact
A logic flaw in macOS allows an attacker with a privileged network position to gain unauthorized access to sensitive user information by bypassing insufficient checks. The vulnerability could expose confidential data, potentially leading to privacy violations or further exploitation by an insider or compromised device.
Affected Systems
Apple macOS versions preceding macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are affected. Any installations with older releases are susceptible to this logic issue.
Risk and Exploitability
The CVSS score of 5.9 indicates medium severity, while the EPSS score of < 1% suggests a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to be in a privileged network position; no public exploits are documented, so the risk is largely confined to environments where internal or compromised network access is possible.
OpenCVE Enrichment