Impact
An issue in the handling of snapshots could allow an application to read protected user data due to insufficient permission checks (CWE‑284). The flaw permits an app to bypass normal safeguards and access confidential files normally protected within the user’s account. Because the problem resides in snapshot logic, any software that creates or retrieves snapshots could be used to retrieve sensitive information.
Affected Systems
Apple macOS is affected. The vulnerability was addressed in macOS Golden Gate 27; earlier releases that have not applied the patch remain vulnerable. Users should verify the operating system build and apply the update if they are running a previous version.
Risk and Exploitability
The CVSS score is 5.5, and the EPSS score is <1%, indicating a very low probability of exploitation, but the flaw enables disclosure of protected data, which is a high impact event. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local or bundled application that performs snapshot operations; an attacker would need to deliver or run a malicious app on the affected Mac. Immediate remediation via patch removes the vulnerability; until then, the risk to confidentiality is significant for unsecured data.
OpenCVE Enrichment