Impact
A buffer overflow (CWE‑120) was discovered in macOS, allowing an application running with root privileges to execute arbitrary code at kernel level. This escalates local, trusted processes to full system control, potentially compromising confidentiality, integrity, and availability for the affected machine.
Affected Systems
Apple macOS is impacted. Versions prior to Sequoia 15.3 are vulnerable, while Sequoia 15.3 contains the fix.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, and the EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring an attacker to run a root‑privileged process to exploit the overflow.
OpenCVE Enrichment
EUVD