Impact
A permissions validation flaw has been corrected in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, indicating that prior to those releases a malicious application could bypass file system permissions and read files it was not authorized to access. The vulnerability results from insufficient privilege checks when accessing restricted files, allowing an attacker to gain unintended data visibility. This could lead to compromise of confidential information or facilitate further attacks if the attacker obtains additional system insights.
Affected Systems
Apple macOS versions 27 (Golden Gate), 15.8 (Sequoia), and 26.7 (Tahoe) are affected by this permissions issue. Users running these releases are at risk when executing validation controls.
Risk and Exploitability
The likely attack vector is a local attacker who can supply or run a malicious application on the system. Based on the description, it is inferred that the vulnerability can be exploited to bypass file-system permissions. An EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The recommended mitigation is to install the patched macOS releases, which resolve the permission checks, thereby eliminating the pathway for unauthorized file access.
OpenCVE Enrichment