Impact
A race condition within Apple macOS operations can allow a malicious application to gain root privileges. The flaw is fixed in version Tahoe 26.6. An attacker exploiting this race condition would compromise confidentiality, integrity, and availability by elevating a local user’s privileges to system level.
Affected Systems
Apple macOS is affected, with the issue addressed in macOS Tahoe 26.6. Systems running earlier versions of macOS may be vulnerable; the precise affected releases are not explicitly enumerated in the available data.
Risk and Exploitability
The CVSS score of 7.8 indicates significant potential impact. The EPSS score is less than 1%, indicating a very low probability of exploitation at present, though it remains a serious vulnerability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a locally installed malicious application that can gain root privileges. No additional prerequisites beyond local execution appear to be required, making this a straightforward privilege‑escalation scenario.
OpenCVE Enrichment