Impact
The flaw enables an application to launch unsigned services on Intel-based Macs, allowing that service to read protected user data. This is an access‑control weakness that could expose confidential information. The vulnerability is resolved by blocking unsigned service launch. Attackers could potentially install or launch an unsigned service that bypasses normal sandboxing.
Affected Systems
Apple macOS platforms, specifically Intel-based Macs running versions older than macOS Sequoia 15.7, macOS Sonoma 14.8 or macOS Tahoe 26. Users of earlier releases are impacted.
Risk and Exploitability
The CVSS score is 5.5, indicating moderate severity. The EPSS score is below 1%, suggesting a very low likelihood of exploitation, and the flaw is not listed in CISA’s KEV catalog. The attack likely requires local or privileged execution to install or launch an unsigned service, and the remedy is to block unsigned services or apply the latest OS updates.
OpenCVE Enrichment
EUVD