Impact
A permissions issue in macOS allows an application to gain root privileges, exposing the system to compromise. The flaw is classified as CWE-269 (Improper Privilege Management) and can be exploited to elevate local privileges to system level, giving an attacker full control over the machine. The impact ranges from data theft to further malware installation and system sabotage.
Affected Systems
Apple macOS versions prior to macOS 26 (the Tahoe 26 release) are vulnerable. The issue was resolved in macOS Tahoe 26, so any system running earlier releases remains at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is below 1%, suggesting a low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. Attack vectors are likely local, where a malicious or compromised application runs with user privileges and then escalates to root. The lack of a public exploitation record means the risk is primarily theoretical until an exploit becomes available.
OpenCVE Enrichment
EUVD