Impact
A permission oversight allows an installed application to change the system’s privacy settings. This improper access control flaw can enable an attacker to toggle privacy controls, potentially exposing personal data or facilitating other attacks that rely on altered privacy behavior. The vulnerability stems from a lack of adequate permission checks before modifying privacy preference files.
Affected Systems
Apple macOS users with operating system versions older than macOS Golden Gate 27 are vulnerable. The fix was deployed in macOS Golden Gate 27, so only installations pre‑2026 versions face this issue.
Risk and Exploitability
The CVSS base score of 5.5 indicates a medium severity, reflecting the potential privacy impact without confirming widespread compromise. The EPSS score of less than 1% suggests a low probability of exploitation under current threat conditions. The flaw is not listed in CISA’s KEV catalog. Based on the description, the attack surface is local; an application running with sufficient user privileges may exploit this degraded permission check. While not currently a high‑risk public threat, the ability to alter privacy configurations warrants timely remediation.
OpenCVE Enrichment