Impact
A maliciously crafted ZIP archive can bypass macOS Gatekeeper’s strict ZIP validation checks, allowing unsigned or tampered software to be executed. Gatekeeper normally enforces code signing before any application runs; the flaw removes that safeguard and enables an attacker to deliver malware that runs with the privileges of the user who opens the archive. The vulnerability is limited to ZIP archives and requires the victim to open or extract the archive, but once bypassed, any contained executable can run.
Affected Systems
Apple macOS releases prior to Sequoia 15.7.8 and Sonoma 14.8.8 are vulnerable; installing those versions or later remediate the validation weakness.
Risk and Exploitability
The exploit requires the attacker to supply a malicious ZIP file and rely on a user or automated process to open it. The CVSS score of 5.5 indicates medium severity, while the EPSS score of less than 1% indicates a low global exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, Gatekeeper operates with elevated privileges as a core security layer, so the potential impact remains notable in environments where the feature is enabled and users frequently open archives.
OpenCVE Enrichment