Description
Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.
Published: 2026-07-14
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorized user of Microsoft Defender for Endpoint on macOS can locally access sensitive personal data that should remain private. The vulnerability is a local information disclosure, classified as CWE-359, allowing an attacker with legitimate Defender privileges to reveal confidential information.

Affected Systems

Microsoft Defender for Endpoint for Mac from Microsoft. No specific affected product versions are listed in the available data.

Risk and Exploitability

The CVSS score of 4.7 indicates a moderate severity level, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. Because the attack requires an authorized local user with Defender access, the likely attack vector is local exploitation rather than network-based.

Generated by OpenCVE AI on July 31, 2026 at 07:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Defender for Endpoint for Mac update that contains the fix.
  • Limit local user permissions so that only trusted administrators can run Defender and access its logs.
  • Enable macOS security features, such as Gatekeeper and the firewall, to reduce the opportunity for local attackers to exploit the application.

Generated by OpenCVE AI on July 31, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.
Title Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft defender For Endpoint
Weaknesses CWE-359
CPEs cpe:2.3:a:microsoft:defender_for_endpoint:*:*:*:*:*:macos:*:*
Vendors & Products Microsoft
Microsoft defender For Endpoint
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Defender For Endpoint
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:56:29.328Z

Reserved: 2026-06-05T14:33:50.831Z

Link: CVE-2026-50657

cve-icon Vulnrichment

Updated: 2026-07-15T13:59:43.265Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:30:04Z

Weaknesses
  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor