Impact
The vulnerability is a permissions issue in Apple macOS that was addressed by improved state management. An application may use the flaw to circumvent the system’s Privacy preferences, potentially gaining access to protected data or services that should be limited by user consent. This bypass compromises user privacy by allowing the software to with elevated permissions it was not granted.
Affected Systems
Affected releases Apple macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Once the fix has been applied through an official update, these versions are no longer vulnerable.
Risk and Exploitability
The EPSS score is < 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV, and the CVSS score is 4.4; however, nature of the flaw, it is inferred that the attacker needs to install or run a malicious application on the device. There are no publicly disclosed exploitation steps or prerequisites beyond application installation.
OpenCVE Enrichment