Impact
The vulnerability is an improper authorization flaw that allows a sandboxed application to read the system pasteboards, which normally should be protected; an attacker can therefore retrieve sensitive user data such as copied text, images, or clipboard history, leading to unauthorized disclosure of personal or corporate information.
Affected Systems
Apple macOS releases older than Golden Gate 27 are affected because they lack the additional sandbox restrictions on system pasteboard access; all versions before this update are susceptible.
Risk and Exploitability
With a CVSS score of 5.5 and an EPSS of less than 1%, the risk is moderate but the likelihood of exploitation is low; the flaw does not appear in CISA’s KEV catalog and is likely to be exploited locally by a sandboxed application that can invoke pasteboard APIs during a user session.
OpenCVE Enrichment