Impact
This update addresses a logic flaw that could allow an application to circumvent the Gatekeeper integrity checks, potentially permitting the installation and execution of unsigned or malicious software. The flaw enables a user or attacker to sidestep policy enforcement that normally restricts applications to trusted sources, which can result in unauthorized code execution and compromise of system integrity. The weakness is classified as an input validation error (CWE‑20).
Affected Systems
Apple macOS; the affected releases are macOS Sequoia 15.7.2, macOS Sonoma 14.8.2 and macOS Tahoe 26.1.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, but the EPSS score of less than 1% shows a low probability of active exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The flaw can most likely be triggered through a user‑initiated action such as installing an application that bypasses Gatekeeper, or by an attacker supplying a crafted signed package that tricks the system into treating it as trustworthy.
OpenCVE Enrichment