Impact
An injection issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.7. An app may be able to gain root privileges. The flaw is classified as CWE‑88, relating to command or privilege escalation. An attacker who can supply crafted input to a vulnerable component could potentially obtain elevated privileges, bypassing the system’s privilege boundaries.
Affected Systems
The vulnerability affects Apple’s macOS products. Versions older than macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Golden Gate 27, and macOS Tahoe 26.7 are vulnerable, while those releases and later provide the fix.
Risk and Exploitability
The CVSS score of 7.8 designates a high‑severity threat. The EPSS score is reported as below 1 %, indicating a very low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local; an application that can inject malicious input into the affected component may trigger the flaw and gain root privileges. Because elevated privileges can be obtained, the impact on confidentiality, integrity, and availability is potentially complete system compromise if the attacker controls a privileged process.
OpenCVE Enrichment