Impact
A file quarantine bypass in macOS Gatekeeper occurs when a maliciously crafted ZIP archive may bypass Gatekeeper checks. The issue has been addressed in selected macOS releases (Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.5). The bypass allows the system to treat the archive as compliant, potentially enabling execution of malicious code without user awareness. This weakness corresponds to CWE‑290 (Authorization Bypass) and CWE‑693 (Security Misconfiguration).
Affected Systems
Vulnerable systems are macOS Sequoia, Sonoma, and Tahoe. The issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.5. Users operating earlier releases may be affected, including all builds prior to those patch releases. The advisory lists only the three major macOS versions, so all legacy releases before the stated patch versions are considered at risk.
Risk and Exploitability
The CVSS score is 5.5, reflecting moderate severity. The EPSS score is below 1%, indicating a low probability of exploitation, and the vulnerability is not listed in CISA KEV, meaning no widespread exploitation has been observed. Nonetheless, a malicious ZIP archive can still bypass Gatekeeper and allow execution of unwanted code if a user opens it, presenting an elevated risk to system integrity on non‑patched macOS systems.
OpenCVE Enrichment