Impact
The vulnerability is an input validation flaw in macOS where untrusted input handling was removed, allowing a malicious application to obtain root privileges. The weakness is classified as CWE‑20 and is explicitly stated to be fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, and macOS Ventura 13.7.6.
Affected Systems
Apple’s macOS operating system is affected, specifically earlier releases of Sequoia, Sonoma, and Ventura. The issue has been resolved in macOS Sequoia 15.5, macOS Sonoma 14.7.6, and macOS Ventura 13.7.6; any earlier versions that have not received these updates remain vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score of less than 1% shows that exploitation is currently unlikely, and the vulnerability is not listed in CISA KEV. Based on the description, a local malicious application that supplies crafted input could trigger the flaw and elevate privileges, making the risk significant despite the low exploitation probability.
OpenCVE Enrichment
EUVD