Impact
The vulnerability arises from insufficient checks in macOS that allow an application to read sensitive user data without proper authorization. This flaw enables an attacker to obtain confidential information from the target device, potentially leading to privacy breaches and further exploitation. The weakness is an improper enforcement of access controls.
Affected Systems
Apple macOS products are impacted, specifically macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. The fix is included in these releases; any earlier versions remain vulnerable.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is not provided in the available data, so the exact severity cannot be quantified, but the nature of the flaw suggests a high risk if an application is able to exploit it. The likely attack vector is local, through a malicious or compromised application running on the user’s device.
OpenCVE Enrichment