Impact
The vulnerability manifests as a permissions issue that allows a malicious application to gain root privileges. Because the flaw stems from broken access control (CWE‑269), an attacker could execute privileged commands or modify system configuration, potentially compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
Apple macOS, specifically versions of macOS Sequoia released prior to the 15.6 update. The issue was addressed in macOS Sequoia 15.6; therefore versions 15.5 and earlier are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1 % suggests a low current likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. The attack vector is inferred to be a malicious application installed or executed on the local machine, taking advantage of insufficient permission checks to elevate privileges.
OpenCVE Enrichment
EUVD