Impact
A permissions flaw was discovered in macOS that allows an application to modify protected areas of the filesystem. The bug is addressed in macOS Sequoia 15.3, Sonoma 14.7.3, and Ventura 13.7.3, implying earlier releases may permit unauthorized changes to system files or directories. Such an ability can undermine the integrity of the operating system, potentially enabling further attacks or persistence mechanisms.
Affected Systems
The vulnerability affects all Apple macOS products. Vulnerable versions include any macOS installation that predates the fixed releases: Sequoia earlier than 15.3, Sonoma earlier than 14.7.3, and Ventura earlier than 13.7.3. Apple users should verify the version of macOS on their devices.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The CISA KEV database does not list this issue, and there is no known active exploitation. The likely attack vector requires local access and sufficient privileges to run the compromised application, though remote exploitation is not indicated by the current information.
OpenCVE Enrichment
EUVD