Impact
A permissions issue in macOS allows applications to read or write restricted files because path validation is insufficient. This flaw means that a malicious or compromised application can access data that should be protected by the operating‑system sandbox. The vulnerability involves improper input validation and access control.
Affected Systems
Apple macOS versions that are affected and that contain the flaw include macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Risk and Exploitability
The EPSS score is <1%, indicating a very low likelihood of exploitation. The CVSS score of 5.5 indicates moderate severity, but the flaw is not listed in the CISA KEV catalog, and it remains a local or application‑level vulnerability. The attack is likely to require the attacker to run or manipulate an application on the affected system, after which the application may browse to a disallowed path and read or modify protected files. The risk is elevated for systems that run applications from untrusted sources or that allow users to supply file paths without rigorous sanitization.
OpenCVE Enrichment