Impact
A race condition in macOS state management was identified, which can allow an application to gain root privileges. The vulnerability is classified as CWE-362, reflecting a synchronization issue that can lead to privileged escalation.
Affected Systems
Affected systems include Apple’s macOS releases, specifically macOS Sonoma 14.8.x and macOS Tahoe 26.x. The fix is delivered in macOS Sonoma 14.8.8 and macOS Tahoe 26.6. Users relying on earlier releases are vulnerable until the update is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 7, indicating a high severity level. The EPSS score is less than 1%, indicating a very low exploitation probability, and the issue is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector would involve a locally running application with elevated privileges exploiting the race condition to elevate to root. Timely patching is crucial to mitigate potential exploitation.
OpenCVE Enrichment