Impact
A downgrade vulnerability that targets Intel‑based Macs allows a malicious or compromised application to bypass recent code‑signing restrictions added by Apple. By exploiting the flaw, the application can read user‑sensitive data that should otherwise be protected. The weakness is identified as CWE‑347, a downgrade flaw typical of improper validation of system components or certificates.
Affected Systems
The issue affects macOS running on Intel processors. The flaw is fixed in macOS Sequoia 15.7.2 and macOS Tahoe 26.1. All Intel‑based Mac systems that have not installed these updates, or any earlier release, remain potentially vulnerable; newer Apple silicon Macs are not affected.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. EPSS is reported at less than 1 %, implying a low risk of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local execution by a malicious or compromised app on an Intel Mac; once the downgrade exploit succeeds, an attacker can gain unauthorized read access to protected data.
OpenCVE Enrichment