Impact
A permissions flaw that allowed an application to trigger a denial‑of‑service was removed by eliminating the vulnerable code in recent macOS releases. The weakness, identified as a missing permission check (CWE‑863), lets a malicious or poorly designed app cause a crash or resource exhaustion, compromising availability of the affected system.
Affected Systems
Apple macOS is affected when the flaw remains unpatched. The issue is resolved in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, and macOS Tahoe 26.1; therefore any older or earlier builds are vulnerable.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate severity. An EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local user or application that attempts to abuse the missing permission check; no evidence of remote exploitation is provided.
OpenCVE Enrichment