Impact
The vulnerable macOS "hdiutil" command could be manipulated to run unintended shell commands, allowing an attacker to execute arbitrary code on the affected system. This operation bypasses normal security controls and grants an attacker full control over the affected machine. The weakness stems from improper handling of command‑line arguments and is consistent with a CWE‑78 style vulnerability.
Affected Systems
Apple macOS systems running a version earlier than Sequoia 15.6, Sonoma 14.7.7, or Ventura 13.7.7 are affected; the issue was resolved by removing the vulnerable code in the releases listed above.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability, yet the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog and appears to require local execution of the hdiutil command, meaning the attacker must either obtain local access or manipulate a user trusted to run the command.
OpenCVE Enrichment
EUVD