Impact
A permissions enforcement flaw allows a malicious application to elevate its privileges to root on Apple mobile and desktop platforms. The weakness is classified as CWE‑862, indicating that the operating system failed to enforce access controls. If exploited, an attacker could gain complete control over the affected device, compromising confidentiality, integrity, and availability.
Affected Systems
Apple iOS, iPadOS, macOS, and visionOS are affected. The fix is delivered in iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, and visionOS 27. Devices running any earlier releases are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests exploitation likelihood is low but present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local; a malicious app must be installed on the device, which then abuses the broken permissions check to obtain root. In environments where untrusted or sideloaded apps are common, the risk is amplified.
OpenCVE Enrichment