Impact
A race condition in macOS state handling was identified that can allow an application to execute arbitrary code with elevated privileges. This flaw, classified as CWE‑362, enables developers or malicious apps to orchestrate a delicate timing race, potentially causing the operating system to elevate the process to root. Once root is gained, the attacker has full control of the system, compromising confidentiality, integrity, and availability.
Affected Systems
Apple macOS versions before Sequoia 15.7, before Sonoma 14.8, and before Tahoe 26 are affected. Devices running these older releases are susceptible unless patched by installing the latest OS update that contains the race‑condition fix.
Risk and Exploitability
The CVSS score of 7 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests that it is unlikely to be widely exploited at present. The flaw is not listed in the CISA KEV catalog, reducing immediate threat awareness. However, the nature of a race condition, combined with the ability to gain root, means that local attackers or compromised applications could succeed. Because the exploit requires precise timing and concurrent operations, it is more complex than a simple remote exploit, but the potential damage is severe.
OpenCVE Enrichment
EUVD