Impact
A flaw in macOS permits an application to write to protected portions of the file system. This vulnerability was fixed by removing the vulnerable code from the operating system. Exploiting this weakness can allow an attacker to replace or tamper with critical system files, potentially compromising the integrity of core OS components.
Affected Systems
Apple macOS versions released before Sequoia 15.4, Sonoma 14.7.5, and Ventura 13.7.5 are affected. Apple has addressed the issue in those patched releases by eliminating the vulnerable code. Systems remaining on earlier releases could permit local applications to modify protected files.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity, while an EPSS score of less than 1% reflects a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that exploitation requires local execution of a malicious application or elevated privileges; a remote attack vector is not explicitly described. The availability of a local exploit coupled with the potential to alter core OS files poses a moderate risk to affected systems.
OpenCVE Enrichment
EUVD