Impact
A logic flaw allows an application to circumvent the Gatekeeper security checks that normally restrict software to signed and trusted sources. While the CVE description does not explicitly state that arbitrary code execution is guaranteed, it is inferred that if an attacker delivers a malicious program that bypasses Gatekeeper, that application will run without standard verification, potentially executing harmful code.
Affected Systems
Apple macOS versions prior to macOS Tahoe 26 contain the issue, as the flaw was fixed in that release.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity, and the EPSS score of below 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the most likely attack scenario involves an attacker providing or facilitating the execution of a specially crafted application that bypasses Gatekeeper checks, typically via a local installation of the program.
OpenCVE Enrichment