Impact
A race condition in macOS allows a local application to break out of its sandbox, giving the application elevated privileges beyond its intended confinement. This flaw can compromise the confidentiality, integrity, and availability of data and processes on the affected system, enabling the malicious app to read protected files, modify system components, or execute arbitrary code with local user rights.
Affected Systems
Apple macOS is affected, specifically the vulnerabilities are fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7. Earlier releases across these major lines remain vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. Although the EPSS score is below 1% and the vulnerability is not listed in CISA KEV, the local nature of the race condition means that any user with the ability to run code on the machine can exploit the flaw. The attack vector is inferred to be local due to the race condition and sandbox escape attributes. The exploitation requires conditions satisfied by the application’s race time access to shared resources.
OpenCVE Enrichment
EUVD