Impact
A race condition exists in macOS that allows a malicious or vulnerable application to read sensitive user data by exploiting improper state management. The flaw arises when concurrent operations and state changes are not correctly synchronized, permitting out‑of‑order execution that bypasses normal access controls. As a result, an attacker could gain confidential information without legitimate authorization, reducing data confidentiality and potentially exposing personal or system‑critical information.
Affected Systems
Apple macOS platforms are affected. Versions preceding macOS Golden Gate 27 contain the flaw; the issue is resolved in macOS Golden Gate 27 and later releases.
Risk and Exploitability
The vulnerability is exploitable from user‑level code; an attacker only needs to run an application that triggers the race condition. The EPSS score is less than 1%, indicating a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The risk is that any application capable of triggering the race could read data intended to be protected, providing a path to data exposure. The CVSS score of 5.9 indicates moderate severity. Timely patching is recommended to mitigate the risk.
OpenCVE Enrichment