Impact
The vulnerability is a parsing flaw in macOS’s handling of directory paths, allowing certain applications to bypass normal security checks and read protected files. The flaw results from inadequate path validation, giving an app the ability to access sensitive user data that should otherwise be restricted. The primary impact is the disclosure of confidential information.
Affected Systems
Apple macOS releases Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 are affected, because the prescribed path‑validation logic was not in place in those versions. Users running any of these releases should verify their system version against the listed updates.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% and absence from the CISA KEV list suggest a low exploitation probability. The likely attack vector is an application that accepts user‑supplied path inputs; exploitation requires the attacker to run code within that application’s context or to gain local execution privileges. The patch mitigates the issue by enforcing stricter path validation.
OpenCVE Enrichment