Impact
An authentication flaw allows a macOS Shortcut to execute with administrator privileges without proper authentication. The vulnerability stems from inadequate state management during Shortcut execution, enabling an attacker to elevate privileges on the affected system. The resulting compromise grants full control of the machine, including the ability to install malware, modify system settings, or exfiltrate data.
Affected Systems
The flaw impacts Apple macOS versions prior to Sequoia 15.4, Sonoma 14.7.5, and Ventura 13.7.5. Users running any earlier release of these operating systems are susceptible to this privilege escalation.
Risk and Exploitability
The CVSS score of 9.8 reflects the severe potential consequences of this vulnerability. Although the EPSS score indicates exploitation probability is below 1%, the flaw is not listed in CISA’s KEV catalog. The attack vector is inferred to require the execution of a malicious Shortcut; an attacker could deliver the Shortcut via one‑click downloads, phishing, or scripts that run automatically.
OpenCVE Enrichment
EUVD