Impact
The vulnerability is a state‑management defect that enables an attacker with root privileges to delete protected system files, potentially compromising operating system integrity. It was addressed through improved state management and is fixed in macOS Sequoia 15.7.4, Sonoma 14.8.4, and Tahoe 26.
Affected Systems
The flaw affects macOS operating systems prior to the release of Sequoia 15.7.4 and Sonoma 14.8.4; any installation that has not been updated to these versions is considered vulnerable.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity, and the EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, and it requires local root access; thus the attack vector is limited to environments where an attacker can already obtain or holds root privileges.
OpenCVE Enrichment