Impact
The vulnerability could allow an application to modify protected parts of the file system. The description does not detail the exact exploitation mechanism, but the associated CWE‑787 suggests a buffer overflow or out‑of‑bounds write. This could compromise system integrity and confidentiality, and may enable privilege escalation if the flaw is triggered in a privileged context.
Affected Systems
Apple macOS is affected; the fix is delivered in macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5. No other versions are confirmed to be vulnerable, but any macOS system not updated to at least one of these releases may still be at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. EPSS indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local: an attacker able to run a malicious or compromised application could potentially trigger the flaw and modify protected filesystem components. If a user runs such software, the exploit could result in system compromise.
OpenCVE Enrichment
EUVD