Impact
A permissions flaw in macOS allows an application to gain root privileges, elevating its authority to full system control. The weakness is classified as CWE‑281, indicating improper restriction of operations within the system. This flaw enables an attacker who can run or trick a compromised app to execute privileged commands, read sensitive data, modify system settings, or install further malware.
Affected Systems
Apple macOS is affected. The issue remains present in versions prior to macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5, and has been remediated in those releases and later.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity. The EPSS score is below 1%, suggesting a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly detailed in the available data; based on the nature of the flaw it is inferred that the exploit likely requires local execution of a malicious application or could be triggered remotely under conditions that allow the app to run with elevated privileges.
OpenCVE Enrichment
EUVD