Impact
The vulnerability stems from insufficient checks in macOS that allow an application to read sensitive user data without proper authorization. This flaw could enable an attacker or a malicious app to expose confidential information, resulting in a confidentiality breach.
Affected Systems
Apple macOS is affected. The fix is carried in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Devices running any of these versions that have not been updated are susceptible.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, suggesting that the vulnerability could lead to a moderate compromise of confidentiality. An EPSS score of < 1% is provided, indicating a very low but non‑zero probability that the vulnerability will be exploited. The vulnerability is not listed in CISA's KEV catalog, so no additional exploitation data is known. The attack is inferred to require an app running on the device, potentially with elevated privileges or from a malicious source, to exploit the missing checks and gain data. The impact remains a confidentiality breach if the vulnerability is leveraged.
OpenCVE Enrichment