Impact
A logic flaw in macOS permits a malicious application to acquire root privileges. The flaw stems from insufficient restrictions on privileged operations, classified as CWE‑269. The vulnerability was corrected by applying tighter access controls in later releases of macOS Sequoia and Sonoma.
Affected Systems
Apple macOS is affected. The issue remains present in versions prior to macOS Sequoia 15.6 and macOS Sonoma 14.7.7; it is fixed in those and later releases of the two operating systems.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while an EPSS of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is installing a malicious app that, once executed, gains elevated privileges; this bypasses normal user privilege separation and enables full system control.
OpenCVE Enrichment
EUVD