Impact
The vulnerability is a permissions issue (CWE-863) and takes advantage of mis‑configured access controls, allowing a malicious or mis‑configured application to read user‑sensitive data it should not access. It arises from insufficient validation of user privileges, resulting in a breach of confidentiality for the affected system. The issue is addressed in Xcode 27 and macOS Golden Gate 27.
Affected Systems
Apple Xcode versions prior to 27 and Apple macOS Golden Gate prior to 27 are impacted.
Risk and Exploitability
The likely attack vector is through mis‑configured or malicious applications running on the system, as the flaw allows an app to bypass access controls and read protected data. This inference is based on the description of the permission bypass. The EPSS score of <1% indicates a very low but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The potential for data disclosure makes it a notable concern whenever an application can be tricked into reading protected data. The flaw is mitigated by applying the available software updates. The CVSS score of 5.5 indicates moderate severity.
OpenCVE Enrichment