Impact
The vulnerability is a permissions issue that can allow a user‑level application to obtain root privileges, constituting a local privilege escalation. The weakness corresponds to CWE‑280, inadequate access control, and would enable an attacker who can execute code as a normal user to perform any operation the operating system permits, including installing software, modifying critical system files, and bypassing security controls.
Affected Systems
Apple macOS is affected, specifically versions of macOS Sequoia and macOS Tahoe that are older than Sequoia 15.7.3 and Tahoe 26.2. The security update that addresses the issue is available in those releases; earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity risk. The EPSS score of less than 1% suggests that exploitation is unlikely at present, and the vulnerability is not listed in CISA's KEV catalog, indicating no known exploits. The attack vector is inferred to be local, as the flaw requires that a malicious application be run by a user—there are no network‑based remote triggers documented.
OpenCVE Enrichment