Impact
A permission misuse in macOS allows an application to bypass its sandbox, enabling unauthorized access to system resources, potentially compromising data integrity and confidentiality.
Affected Systems
Apple macOS is affected, but the issue has been fixed in Sequoia 15.7.2, Sonoma 14.8.2, and Tahoe 26.1; earlier releases prior to these contain the vulnerability.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate to high severity, while an EPSS score of less than 1% suggests low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, where a malicious application or code running with user privileges could break out of its sandbox, potentially escalating privileges within the macOS environment.
OpenCVE Enrichment