Impact
The vulnerability arises from insufficient checks in macOS that allow an application to read sensitive user data without proper authorization. This flaw enables an attacker to obtain confidential information from the target device, potentially leading to privacy breaches and further exploitation. The weakness is an improper enforcement of access controls.
Affected Systems
Apple macOS products are impacted, specifically macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. The fix is included in these releases; any earlier versions remain vulnerable.
Risk and Exploitability
The EPSS score of < 1% indicates a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.5 indicates a moderate severity. The flaw’s nature—unauthorized access to sensitive user data—implies a potentially significant privacy impact if an application exploits it. Based on the description, it is inferred that the most likely attack vector is local, via a malicious or compromised application executing on the device.
OpenCVE Enrichment