Impact
This vulnerability allows an application to improperly elevate its privileges and gain root access on macOS. The flaw is a Permission Management weakness (CWE-284) whereby the system fails to enforce correct privilege boundaries. If exploited, the attacker can execute arbitrary code with administrative rights, potentially compromising system integrity, confidentiality, and availability.
Affected Systems
Apple macOS systems are affected, specifically those running macOS Golden Gate version 27 or earlier, macOS Sequoia 15.8 or earlier, or macOS Tahoe 26.7 or earlier. These versions have not yet implemented the improved checks required to prevent privilege escalation. Any applications installed on these systems may be maliciously exploited by attackers.
Risk and Exploitability
The CVSS score of 7.8 indicates that this is a high‑severity vulnerability. EPSS is not available, so the exploitation likelihood be local, requiring presence of the vulnerable application. The vulnerability is not listed in the CISA KEV catalog. Until the patch is applied, any user with access to these macOS versions could potentially gain root privileges by running a compromised app.
OpenCVE Enrichment