Impact
The vulnerability is an authorization flaw in macOS that can allow an application to access sensitive user data it should not be able to read, which in turn can lead to unintended disclosure of private information. It is inferred from the description that the flaw originates from improper access control and therefore affects the confidentiality of user data. No explicit statement is provided about the extent of impact beyond data leakage.
Affected Systems
Apple macOS prior to macOS Golden Gate 27 and prior to macOS Sequoia 15.8 is affected.
Risk and Exploitability
The EPSS score of less than 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. The flaw involves improper access control, allowing any application running on the system to potentially read or exfiltrate sensitive data; it is inferred that this is a consequence of the authorization issue described. While the current exploitation probability remains low, it is inferred that local attackers could leverage this weakness to access private information, making timely patching and monitoring important.
OpenCVE Enrichment