Impact
The vulnerability is an improper access control flaw (CWE‑284) that allows an application running inside the macOS sandbox to breach its confinement. An attacker who can run or influence the affected application could gain privileges beyond the sandbox, compromise system integrity, and potentially access or modify protected data.
Affected Systems
The flaw affects macOS environments running versions prior to macOS Sequoia 15.4, as the issue is addressed in that release. Users of these earlier macOS versions are potentially exposed.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation would be local and require execution of the compromised sandboxed application, making it less likely to be leveraged remotely.
OpenCVE Enrichment
EUVD