Impact
A downgrade vulnerability affecting Intel-based Mac computers was addressed with additional code-signing restrictions. The flaw allows an application to gain unauthorized access to user-sensitive data. The weakness is categorized as CWE-347.
Affected Systems
Apple macOS running on Intel processors. The vulnerability is fixed in macOS Sequoia 15.7.3 and macOS Tahoe 26.2, but earlier releases of Sequoia and Tahoe remain affected.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector probably requires the ability to install or run unauthorized, incorrectly signed applications, which typically demands local user privileges or a compromised system. No public exploit is known and the risk to unpatched systems is considered modest but non‑negligible.
OpenCVE Enrichment