Impact
This vulnerability allows a malicious application to leak sensitive user information, exposing data that should remain private. The flaw arises from improper state management within the operating system, which can be exploited to read arbitrary data from the device. It is a CWE-200 Information Exposure vulnerability, indicating a weakness in confidentiality protection.
Affected Systems
Apple macOS (versions prior to Golden Gate 27) and Apple watchOS (versions prior to Golden Gate 27) are affected. The issue is fixed in macOS Golden Gate 27 and watchOS 27.
Risk and Exploitability
CVSS Score of 5.5 indicates medium severity, and EPSS < 1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local: a malicious application that the user installs or runs on the device can trigger the information leak. Because the flaw does not require network access or elevated privileges beyond the owning user, the overall risk remains moderate but potentially significant for sensitive data exposure.
OpenCVE Enrichment