Impact
A permission-related vulnerability was found in Apple macOS that enables a malicious application to obtain root privileges. The flaw is mitigated by adding additional restrictions, but unless the fix is applied, an attacker can run code with system‑level access, potentially compromising confidentiality, integrity, and availability of the affected device. This issue is classified an elevation of privilege weakness.
Affected Systems
All macOS releases older than macOS Sequoia 15.7.8 or macOS Tahoe 26.6 contain this vulnerability. Versions preceding these updates are susceptible until the corresponding security update is installed.
Risk and Exploitability
The CVSS score of 7.8 indicates a high impact, and the EPSS score is < 1%, implying a low probability of exploitation. The description indicates that a malicious app can exploit the permission gap to elevate privileges. The vulnerability catalog. Based on the description, the likely attack vector is a malicious application that runs with local or remote code execution capability to gain root access.
OpenCVE Enrichment