Impact
The vulnerability is a permissions issue that allows a malicious application to gain root privileges on affected macOS versions. It results in full control over the system, enabling an attacker to modify any system files, install persistent software, or exfiltrate data. The weakness corresponds to CWE-269, a privilege escalation flaw.
Affected Systems
Apple macOS. Versions prior to macOS Sequoia 15.4, macOS Sonoma 14.7.6, and macOS Ventura 13.7.6 are vulnerable. The issue was fixed in those specific releases.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS < 1% shows a very low likelihood of exploitation in the wild at present. The vulnerability is not listed in CISA KEV catalog. The likely attack vector is local, requiring an application or script to execute with elevated privileges. Once exploited, the attacker obtains root-level control. The conditions for exploitation are limited to environments where a malicious or compromised application can run.
OpenCVE Enrichment
EUVD