Impact
An input validation flaw in Apple macOS allows an unprivileged application to read restricted files, thereby compromising data confidentiality. The flaw stems from failure to properly sanitize or constrain user‑controlled data used to locate files, enabling a crafted request to reference protected resources. As a result, confidential or system‑level files may be disclosed to an application that should not ordinarily have access.
Affected Systems
The vulnerability affects Apple macOS releases prior to the inclusion of the fix: macOS Golden Gate before version 27, macOS Sequoia before 15.8, and macOS Tahoe before 26.7. Any macOS install newer than those releases has the patch applied and is considered mitigated.
Risk and Exploitability
The EPSS score of less than 1% indicates that exploitation of this vulnerability is currently unlikely to be observed. The CVSS score of 5.5 reflects moderate severity, indicating potential moderate impact on confidentiality without evidence of widespread exploits. Because the flaw can be triggered by supplying crafted input, the most probable attack vector is local, inferred from the requirement for an application to provide input. An attacker who can execute software on the target machine could read protected files, leading to confidentiality breaches. This vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment