Impact
A permissions flaw allows a malicious app to elevate its privileges to root, giving the attacker full control over the system. This weakness is a classic example of a Permission Modification error (CWE-276) and results in both integrity and confidentiality loss when exploited.
Affected Systems
Apple macOS versions prior to the updates that introduce the fix are affected. The issue is resolved in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6, so any installation of those or earlier releases is susceptible.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score for this vulnerability is < 1%, indicating a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local application executed by a user or automatically loaded scenario; remote exploitation is not documented in the provided data.
OpenCVE Enrichment