Impact
An application can modify protected parts of the file system due to improper access control (CWE-284), potentially altering essential system files or configurations and compromising macOS integrity.
Affected Systems
Apple macOS users running versions prior to the security fixes are affected. The issue was resolved in macOS Sequoia 15.7, macOS Sonoma 14.8, and macOS Tahoe 26. Any earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate impact if exploited. The EPSS score of less than 1 % suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is local, requiring the installation or execution of a malicious or compromised application that contains the vulnerable code. An attacker with the ability to run such code could gain elevated privileges sufficient to modify protected system files.
OpenCVE Enrichment
EUVD