Impact
An improper input validation flaw in Apple macOS allows an attacker that can launch a malicious application to execute arbitrary binaries on a trusted device. The flaw permits the attacker to run any binary as the current user, resulting in full local code execution and compromising device integrity. The weakness is classified as CWE‑20 Input Validation.
Affected Systems
The vulnerability affects Apple macOS versions prior to macOS Sequoia 15.6 and macOS Sonoma 14.7.7. Any installation of Sequoia 15.0 through 15.5 or Sonoma 14.0 through 14.7.6 is at risk. The issue has been fixed in the released updates mentioned above.
Risk and Exploitability
With a CVSS score of 9.8, the risk is severe. The EPSS score of less than 1 % indicates a low likelihood of widespread exploitation at present, and the flaw is not listed in CISA’s KEV catalog. The likely attack vector is a malicious application executed locally on the device, exploiting the faulty input handling to launch arbitrary binaries.
OpenCVE Enrichment
EUVD