Impact
The vulnerability is a permissions flaw characterized by CWE‑276, allowing a malicious application to gain privileged access. With root privileges, an attacker could take full control of the system, exfiltrate or modify data, install back‑doors, or launch additional attacks.
Affected Systems
Apple macOS releases prior to the following patched versions are vulnerable: Sequoia versions older than 15.7.8, Sonoma versions older than 14.8.8, and Tahoe versions older than 26.6. All current macOS releases newer than or equal to those patch releases contain the fix.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the EPSS score of <1% suggests exploitation is unlikely but not impossible. The flaw is not listed in CISA KEV. A local attacker who can install or execute an application is likely to exploit the flaw to elevate privileges, as no network‑based vector is documented in the available data.
OpenCVE Enrichment