Impact
The vulnerability arises from missing validation checks that enable an application to read sensitive user data, such as personal information, credentials, or configuration settings, without explicit permission. This flaw represents an information disclosure weakness, allowing an unauthorized party to access confidential data that should be protected by the operating system's privacy controls.
Affected Systems
Apple macOS systems whose versions are older than the releases that contain the fix—specifically prior to macOS Golden Gate 27, prior to macOS Sequoia 15.8, and prior to macOS Tahoe 26.7—remain susceptible. All releases before these point releases are considered vulnerable.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity, while the EPSS figure of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, reducing urgency for immediate action beyond patching. Attackers would need to execute a malicious application locally on the affected can be leveraged by an installed app, implying a local code execution scenario.
OpenCVE Enrichment