Impact
The vulnerability arises from insufficient validation of symbolic links in macOS. This path handling flaw could allow an attacker to craft or manipulate symbolic links to read or alter files outside the intended directory structure. The weakness corresponds to CWE‑59 (Path Traversal). Potential consequences include unauthorized file access or modification, which may compromise confidentiality or integrity of sensitive data.
Affected Systems
Apple macOS devices running versions older than macOS Sequoia 15.4, macOS Sonoma 14.7.5, or macOS Ventura 13.7.5 are susceptible. Systems with these or earlier releases may be impacted until the updates are applied.
Risk and Exploitability
According to the CVSS score of 5.5, the vulnerability is considered moderate. The EPSS score of < 1% indicates a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The likely attack vector is local, involving creation or following of symbolic links within the operating system, as no remote exploitation mechanism is described in the advisory.
OpenCVE Enrichment
EUVD