Impact
A path handling flaw was found in Apple macOS where inadequate validation could allow an application to manipulate filesystem paths. If exploited, the flaw could grant the application root privileges, providing full control over the affected machine, enabling data tampering, persistence, and other high‑impact consequences.
Affected Systems
Apple macOS Golden Gate, macOS Sequoia, and macOS Tahoe are the affected product families. The issue is resolved in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Systems running earlier releases remain vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, which indicates moderate to high severity. The EPSS score is < 1%, suggesting a very low probability of exploitation. The issue is not listed in the CISA KEV catalog. The likely attack vector is local privilege escalation, inferred from the description that an application could gain root privileges. Although no publicly available exploit is known, the potential impact of a successful exploitation remains significant.
OpenCVE Enrichment