Impact
A race condition (CWE‑362) is described where concurrent processes can access and modify shared data simultaneously, allowing a malicious or poorly behaved application to read protected user data. The description notes that Apple added validation checks in macOS Tahoe 26.6 to prevent the timing issue that enables the data exposure. The flaw permits read‑only access to confidential information but does not explicitly state privilege escalation or remote execution.
Affected Systems
The advisory indicates the fix is only applied in macOS Tahoe 26.6; therefore, it is inferred that all earlier releases of Apple macOS are potentially vulnerable, even though the exact versions are not enumerated. Users running any macOS version before 26.6 should consider themselves at risk.
Risk and Exploitability
The CVSS score of 4.7 signals moderate severity, while the EPSS score of less than 1 % reflects a very low probability of exploitation. The issue is not listed in the CISA KEV catalog. The description implies that exploitation likely requires an application to be executed locally on the affected system to trigger the race condition, as the vulnerability is triggered by concurrent, local processes. The impact is a confidentiality breach through read‑only exposure of protected data. No evidence suggests remote access or privilege escalation is necessary.
OpenCVE Enrichment