Impact
An application can bypass launch constraint protections and execute malicious code with elevated privileges, a classic privilege escalation flaw. The weakness is classified as CWE‑269: Improper Privilege Management. The vulnerability allows an attacker to run code with higher permissions than intended, potentially compromising data integrity and confidentiality for the affected system.
Affected Systems
Apple macOS systems are affected. The issue was fixed in macOS Sequoia 15.7.3 and macOS Tahoe 26, meaning earlier releases of these macOS versions are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is less than 1 %, showing a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The attack likely requires a local application that can manipulate launchd to enforce the bypass, as no remote trigger is indicated.
OpenCVE Enrichment