Impact
A permissions flaw in macOS allows a malicious application to bypass security restrictions and obtain root privileges. This weakness stems from improper enforcement of least‑privilege controls (CWE‑732) and could let an attacker execute any code, modify system files, and compromise the entire operating system. The attack could be launched from a local malicious app that the user installs or runs on the machine.
Affected Systems
Apple macOS, including all releases prior to macOS Sequoia 15.6. The issue was resolved in macOS Sequoia 15.6, so systems running earlier versions or earlier point releases are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity level, but the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, a local attacker who succeeds in running a malicious app can gain root access, giving full control over the affected system. The risk is therefore significant for any environment where privileged binaries could be introduced or where untrusted applications might be executed.
OpenCVE Enrichment
EUVD