The issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access sensitive user data.
No PoCs from references.
- https://github.com/fkie-cad/nvd-json-data-feeds