Impact
A permissions issue in macOS allows applications to read protected user data that they should not be able to access. This flaw effectively grants an application elevated privileges to sensitive information, leading to potential confidentiality violations. The weakness is an example of improper access control (CWE‑269).
Affected Systems
Apple macOS versions affected include Golden Gate 27, Sequoia 15.8, and Tahoe 26.7. Newer releases are not mentioned.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of < 1% shows a low probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. An attacker who can install or run a malicious application on the target system might exploit the permission lapse to read protected user data. The likely attack vector is local, as it requires legitimate execution of the app on the machine.
OpenCVE Enrichment