Impact
An authorization flaw in macOS permits applications to read sensitive user data beyond the intended scope. The vulnerability allows an untrusted or malicious application to access data that should be restricted, leading to a direct breach of confidentiality.
Affected Systems
Apple macOS versions released before Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 are impacted. Users running earlier releases are at risk; upgrading to the specified cutoff versions or later protects against the flaw.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation yet. Attackers would likely need to deliver or install a malicious application on the affected macOS system, implying a local or compromised application vector.
OpenCVE Enrichment