Impact
The flaw is a path handling issue that allows an application to break out of its sandbox, granting access to files and resources outside its intended scope. The weakness, identified as CWE-22, can enable unauthorized file system access. The CVSS score of 4.0 indicates a moderate severity, reflecting the potential for significant impact if successfully exploited.
Affected Systems
Apple macOS systems are affected. The vulnerability exists in releases prior to macOS Sequoia 15.6, Sonoma 14.7.7, and Ventura 13.7.7. Any machine running a pre‑patch version of these operating systems is potentially vulnerable.
Risk and Exploitability
The EPSS score is below 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting low likelihood of widespread exploitation at present. Attackers would need to supply a crafted path or file name to a local or sandboxed application; once inside the sandbox, the application could read or modify files beyond its permitted area. Given the local nature of the vector and the moderate CVSS, the overall risk is moderate but warrants timely remediation.
OpenCVE Enrichment
EUVD