Impact
An application may be able to break out of its sandbox, allowing it to perform operations that it should not be permitted to execute. The weakness is classified as an authorization bypass (CWE-284) and results in a moderate severity risk as reflected by the CVSS score of 5.2.
Affected Systems
The flaw affects Apple macOS prior to the release of macOS Sequoia 15.7.2 and macOS Tahoe 26.1. All earlier versions of these operating systems are susceptible until the fixes shipped in the mentioned releases are applied.
Risk and Exploitability
The CVSS score indicates a moderate risk, and the EPSS score of less than 1 % suggests a very low likelihood of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to involve an application that already runs on the system; an adversary might introduce a malicious or compromised app that leverages the sandbox escape to increase its privileges.
OpenCVE Enrichment