Impact
A buffer overflow vulnerability in macOS allows a malicious application to gain kernel privileges and execute arbitrary code. The flaw stems from improper memory handling, enabling overwriting of critical kernel data structures. Successful exploitation results in local attackers achieving complete control of the affected system with no additional privileges needed.
Affected Systems
Apple macOS versions before Sequoia 15.4, Sonoma 14.7.5, and Ventura 13.7.5 are affected. The issue is fixed in the stated releases and any newer macOS updates.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local and requires the attacker to run a compromised application or deliver malicious content that exploits the underlying kernel component.
OpenCVE Enrichment
EUVD