Impact
A logic flaw in macOS allows an application to modify protected file system areas. This flaw results in the potential alteration of critical system files, which can compromise system integrity and enable further malicious activity. The weakness is classified as a privacy violation (CWE‑200).
Affected Systems
Apple macOS versions prior to Sequoia 15.4, Sonoma 14.7.5, and Ventura 13.7.5 are vulnerable. Any macOS installation without these updates may allow an app to modify protected parts of the file system.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk, while the EPSS score of less than 1% suggests a low likelihood of exploitation. It is not listed in the CISA KEV catalog, implying no known widespread public exploits. The flaw is typically exploitable by a local application that runs with sufficient privileges, potentially requiring user interaction or local code execution, and could be used to weaken system integrity or persist malicious code.
OpenCVE Enrichment
EUVD