Impact
A permissions issue was addressed with improved validation. This issue allows an application to read sensitive user data beyond intended access controls.
Affected Systems
Apple macOS. The vulnerability applies to macOS versions prior to Golden Gate 27, Sequoia 15.8, and Tahoe 26.7.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. An attacker can use a malicious or compromised application installed on the target system to read protected information by bypassing standard permission checks. The attack requires local execution of the application; no remote execution is required, but the impact is moderate to high for affected systems until the patch is applied.
OpenCVE Enrichment