Impact
An issue in Apple macOS allowed an application to modify protected portions of the file system, which can cause a denial of service by corrupting essential system resources or rendering the system unusable. The vulnerability arises from improper access controls that let privileged or malicious code bypass normal file system safeguards. The impact is loss of availability for the affected machine, potentially leading to system instability or a complete loss of functionality.
Affected Systems
Apple macOS products including macOS Sequoia, macOS Sonoma, and macOS Tahoe versions preceding the patch releases. The vulnerability was addressed by eliminating the problematic code and fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5.
Risk and Exploitability
The risk is significant as any compromised application running on the system could exploit this flaw to cause a denial of service. The CVSS score is 7.5, and the EPSS score is < 1%, indicating a low probability of exploitation but a high potential impact. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been observed in widespread exploitation. The likely attack vector involves a malicious or compromised application with sufficient privileges to write to protected filesystem locations.
OpenCVE Enrichment