Description
A privacy issue was addressed by removing sensitive data. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive user information.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A privacy flaw in macOS allows an application to leak sensitive user information. The vulnerability was fixed by removing or protecting the sensitive data that could be accessed by an app. The flaw can expose private data, potentially impacting user confidentiality if an attacker can cause the application to reveal such information.

Affected Systems

Vulnerable macOS releases include Apple macOS versions prior to macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. The bug was addressed in the indicated patch releases for each platform.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate impact with potential for information disclosure, while the EPSS score of < 1% indicates a very low probability of exploitation. Attackers would need a malicious or compromised application that can access the exposed sensitive data; the exact attack vector is not detailed but is inferred to require the app to execute code that triggers the leak. The flaw is not listed in CISA’s KEV catalog, so there are no known large‑scale exploitation reports. The weakness is identified as CWE-200.

Generated by OpenCVE AI on August 4, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to macOS Sequoia 15.7.8 or later, macOS Sonoma 14.8.8 or later, or macOS Tahoe 26.6 or later as provided by Apple.
  • Reboot the system after the upgrade to ensure the new security settings are fully applied.
  • Configure System Settings > Privacy to limit the application’s access to sensitive data, disabling data sharing for apps that do not require it.

Generated by OpenCVE AI on August 4, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title macOS Privacy Flaw Enabling Sensitive Data Leak

Sun, 02 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title macOS Privacy Flaw Enabling Sensitive Data Leak

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A privacy issue was addressed by removing sensitive data. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive user information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:09:14.924Z

Reserved: 2026-07-20T18:09:24.049Z

Link: CVE-2026-64710

cve-icon Vulnrichment

Updated: 2026-07-28T14:09:06.236Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:10.370

Modified: 2026-07-28T18:06:00.097

Link: CVE-2026-64710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:30:10Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor