Impact
The vulnerability involves an Improper Access Control flaw (CWE‑284) in the macOS Shortcuts app that permits a shortcut to bypass sensitive settings, such as user consent prompts. A malicious shortcut could therefore execute actions without the user being prompted, potentially granting unintended access to system resources or personal data. The flaw was addressed by adding an additional consent dialog in newer macOS releases.
Affected Systems
All macOS versions prior to macOS Sequoia 15.4, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7 are affected. Any device running those legacy releases may be vulnerable, regardless of hardware, as the issue resides in the system Shortcuts framework.
Risk and Exploitability
The CVSS score of 9.8 indicates a high‑severity flaw that could enable an attacker to circumvent user consent. The EPSS score of less than 1 % suggests the probability of exploitation is low at present, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation likely requires the user to run a shortcut crafted to exploit the bypass; therefore the attack vector is local and depends on social engineering or malicious shortcut distribution.
OpenCVE Enrichment
EUVD