Impact
An authorization flaw in macOS state management—identified as CWE‑863—can let an application read or manipulate sensitive user data that it should not be allowed to see. The weakness enables an attacker to gain access to personal information, credentials, or other confidential data through a compromised application. It is a privilege‑management issue that arises when the operating system fails to properly enforce boundaries between processes.
Affected Systems
Apple macOS Golden Gate versions earlier than 27, Sequoia earlier than 15.8, and Tahoe earlier than 26.7 are vulnerable. Systems running these or older releases are at risk until updated to the specified fixed versions.
Risk and Exploitability
The EPSS score is reported as less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that exploitation is neither widely observed nor actively marketed. The flaw is local in nature, meaning an attacker must deliver or execute code on the target machine, likely through a local or supply‑chain vector. Nonetheless, because the affected data can be highly confidential, the potential impact warrants immediate remediation.
OpenCVE Enrichment