Impact
An integer overflow condition in macOS allows a local user to potentially gain higher privileges by supplying crafted input that bypasses bounds checks. The flaw has been fixed in the recent releases of Sequoia, Sonoma, and Ventura, meaning that exploitation would be limited to earlier builds. The vulnerability is categorized as incorrect access control, which is a high‑risk weakness that can lead to arbitrary code execution if successfully triggered.
Affected Systems
Apple macOS is affected. The vulnerability is mitigated in macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5. All earlier versions of these operating systems remain susceptible.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1 % reflects a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector is most likely local; an attacker must have access to a user session or execute malicious input on the target system to trigger the overflow.
OpenCVE Enrichment
EUVD