Impact
A race condition in macOS state handling permits an application to gain higher privileges. The flaw stems from improved state handling, potentially leading to unintended privilege escalation.
Affected Systems
Apple macOS systems are impacted. The issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.4, meaning earlier releases of these operating system families are vulnerable unless otherwise patched.
Risk and Exploitability
The CVSS score of 7.0 reflects a medium-to-high severity impact. The EPSS score, which is less than 1%, indicates that, while exploitation is possible, the likelihood in the wild is very low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local, involving a malicious or compromised application attempting to elevate privileges. Exploitation would require the ability to run an application with user-level access and rely on the race condition to gain higher privileges.
OpenCVE Enrichment