Impact
An authorization flaw driven by inadequate state management lets an application on macOS or watchOS read Bluetooth device information that it should not normally be able to access. The primary effect is the potential disclosure of Bluetooth identifiers, names, or related metadata, which could be used for privacy concerns. No capability to execute code or cause denial of service is indicated in the available description.
Affected Systems
Apple macOS and watchOS systems running versions prior to macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, and watchOS 27 are affected. The fix is included in these OS releases and later.
Risk and Exploitability
The CVSS score is 3.5 and the EPSS score is less than 1%, indicating a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local: an application installed or running on the device with the standard user context may exploit the flaw. No evidence of remote exploitation or additional prerequisites is reported.
OpenCVE Enrichment