Description
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A logic issue in macOS’s internal checks allows an application to locate and read sensitive user data that should not be accessible. The flaw was identified and addressed by adding stricter validation, and the vulnerability is fixed in Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6. Until the update is installed, a malicious or compromised app could read protected data.

Affected Systems

Affected are Apple macOS releases prior to the security patches: Sequoia 15.x, Sonoma 14.x, and Tahoe 26.x. The issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Systems running earlier minor or patch versions of these major releases are considered vulnerable.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting that known exploitation activity is low. The flaw can be leveraged by a malicious application or a local attacker to retrieve protected data. The attack vector is most likely local; remote exploitation would require additional conditions that are not documented. While no active exploits are documented, the vulnerability represents a medium risk until mitigated. The CVSS score of 5.5 indicates medium severity, and this rating combined with the low EPSS confirms the moderate potential impact.

Generated by OpenCVE AI on August 3, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest macOS update that includes the fix for Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6.
  • If an upgrade is not immediately possible, restrict installation of third‑party applications that could exploit the logic flaw and monitor system activity for unexpected data access.
  • Implement application whitelisting or restrict execution of unknown binaries to reduce the attack surface.

Generated by OpenCVE AI on August 3, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Logic Issue Allowing App Access to Sensitive User Data on macOS

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Logic Issue Allowing App Access to Sensitive User Data on macOS
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T15:03:27.881Z

Reserved: 2026-07-20T18:09:47.192Z

Link: CVE-2026-64723

cve-icon Vulnrichment

Updated: 2026-07-28T15:02:04.284Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:11.253

Modified: 2026-07-28T18:05:49.877

Link: CVE-2026-64723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:30:04Z

Weaknesses