Impact
The vulnerability is a permissions flaw that allows a malicious application to obtain root privileges on macOS and visionOS. The weakness corresponds to inappropriate authorization checks (CWE-862).
Affected Systems
Apple’s macOS and visionOS are affected. Any version released before macOS Tahoe 26 and visionOS 26 may contain the flaw. The fix is included in macOS Tahoe 26 and visionOS 26; earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity flaw, but the EPSS score of less than 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog, and no public exploit has been reported. A malicious app that is installed on or executed by the target system can take advantage of this lack of proper authorization to elevate privileges to root, potentially allowing complete control over the device.
OpenCVE Enrichment
EUVD