Impact
A race condition in macOS state handling can allow an application to gain root privileges. The issue is a concurrency flaw that can lead to elevated access for a malicious app, enabling any actions performed as the system user.
Affected Systems
Apple macOS products are affected, including all versions prior to macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6, which contain the fix.
Risk and Exploitability
The CVSS score of 7 indicates a high severity. The EPSS score of less than 1% indicates a very low, but nonzero, probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The description does not specify a particular attack vector; it is inferred that a local attacker that can run code on the system may exploit the race condition and obtain root access.
OpenCVE Enrichment