Impact
A local permission validation flaw allows a user with limited rights to gain elevated privileges on macOS. The weakness, classified as CWE‑276, permits the attacker to bypass intended access controls and assume higher system permissions, compromising confidentiality, integrity, and availability of data and services on the affected machine.
Affected Systems
Apple macOS is affected. Versions prior to macOS Sequoia 15.3, Sonoma 14.7.3, and Ventura 13.7.3 are vulnerable to this local privilege escalation issue.
Risk and Exploitability
The CVSS rating of 7.1 signals a high severity vulnerability, while an EPSS score of less than 1% indicates a very low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. An attacker who can run code locally on the device can exploit this flaw, but the description does not provide evidence for remote or network-triggered exploitation; based on available information, it is inferred that remote exploitation is not supported.
OpenCVE Enrichment
EUVD