Impact
An input validation flaw in macOS allows applications to read arbitrary files by bypassing file access controls. This can let an attacker obtain sensitive data such as configuration files, credentials, or other private information, leading to confidentiality compromise.
Affected Systems
The vulnerability affects Apple macOS in releases that are still using the unpatched input handling, including macOS Golden Gate prior to version 27, macOS Sequoia prior to 15.8, and macOS Tahoe prior to 26.7.
Risk and Exploitability
The CVSS score of 6.5 indicates the vulnerability severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog, implying no known public exploits. Attackers would need to supply crafted input to an affected application or compromise a local user session, so the threat is primarily local or privilege‑local. While the risk of widespread exploitation is low, the potential for data exposure makes timely remediation important.
OpenCVE Enrichment