Impact
The vulnerability is a permissions issue that allows an application to read sensitive user data without proper authorization. It is a moderate severity flaw (CVSS 5.5) and is classified as CWE-863. If an attacker can install or run a malicious application, that application may be able to access data it is not permitted to read, exposing private information.
Affected Systems
Apple macOS users running any release earlier than macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 are vulnerable. The issue is resolved in those releases and any subsequent updates.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation (< 1 %). The CVSS score of 5.5 reflects moderate impact for unauthorized data access. The flaw is not listed in the CISA KEV catalog, suggesting no widespread exploitation publicly known. An attacker would typically need to deliver or run an untrusted application, which could then read privileged data bypassing normal permission checks due to the flawed authorization logic.
OpenCVE Enrichment