Impact
A race condition can allow an application to escape its sandbox. The flaw was corrected with additional validation and fixed in macOS Sequoia 15.1. If exploited, the attacker could gain privileges beyond the sandbox, enabling execution of arbitrary code.
Affected Systems
Apple macOS systems, particularly those running versions prior to Sequoia 15.1. The vulnerability impacts the operating system’s sandbox enforcement mechanism. Affected versions are all earlier releases of macOS before the 15.1 update.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. EPSS under 1% suggests a low probability of current exploitation. The issue is not listed as a known exploited vulnerability, but its high severity and potential to bypass sandbox justify urgent remediation. Attackers would need to trigger the race condition within the sandbox environment, which could be feasible in some contexts.
OpenCVE Enrichment