Impact
A logic issue in Apple macOS allows an application to intercept network connections that are intended for another process, potentially enabling unauthorized data capture or modification before the data reaches its intended destination. This flaw can be exploited by any app taking advantage of the weakened restrictions, thereby compromising the confidentiality or integrity of network traffic associated with other processes. The weakness is a classic example of improper handling of inter‑process networking controls, enabling an attacker to read or alter traffic that should remain isolated to a separate process.
Affected Systems
Apple macOS systems running versions prior to macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, or macOS Tahoe 26.6 are affected. Users of these operating systems should verify that they are running the mentioned patched releases to eliminate the vulnerability.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, which suggests a lack of public evidence of exploitation at this time. The CVSS score of 9.8 signals a critical severity. Nevertheless, the problem can be exploited by any application that succeeds in hijacking the system's network connection handling logic; such an attack would likely require local execution privileges (inferred) but does not appear to be restricted to remote exploitation. The severity therefore depends heavily on the user's configuration and threat landscape, yet the ability to tap into other processes’ network traffic remains a high‑impact concern for systems where sensitive data is transmitted.
OpenCVE Enrichment