Impact
An authorization flaw in macOS, caused by improper state management, permits an application running on the user’s machine to read sensitive information it should not normally access. The vulnerability was fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, and is associated with CWE‑285 (Improper Authorization) and CWE‑863 (Access Control for Sensitive Data). The weakness arises from the operating system’s failure to reset state correctly, allowing a malicious or compromised app to bypass normal permission checks and read protected data.
Affected Systems
Any macOS release older than macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 is affected because those versions lack the state‑management fix introduced in the newer releases.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, the CVSS score of 5.5 denotes moderate potential impact. An attacker would need to deliver a malicious or credential‑stolen application that the user runs locally; no kernel‑level privilege escalation is required. The resulting compromise is limited to environments where an untrusted application is executed, primarily causing privacy violations by exposing sensitive user data.
OpenCVE Enrichment