Impact
A parsing problem in macOS directory path handling allowed applications to bypass normal access controls. Malformed paths could cause the system to resolve to locations not intended by the app, granting access to files that belong to other users. The potential result is disclosure of private data that an app might read without the users’ consent. The weakness arises from insufficient validation of user supplied path components and is associated with input validation flaws.
Affected Systems
Apple macOS versions Golden Gate 27 and Sonoma 14.8.8 are affected. Devices running those releases remain vulnerable until the update is applied.
Risk and Exploitability
Because EPSS information is not available and KEV status is not listed in the CISA Known Exploited Vulnerabilities catalog, the exploitation probability is unknown. The CVSS score is not disclosed, but the flaw can be exploited by any application able to supply malformed path strings, potentially leading to local data leakage. No official workaround exists; the only mitigation is to install the vendor‑supplied update.
OpenCVE Enrichment