Impact
This vulnerability allows an application to improperly elevate its privileges and gain root access on macOS. The flaw is a Permission Management weakness (CWE-284) whereby the system fails to enforce correct privilege boundaries. If exploited, the attacker can execute arbitrary code with administrative rights, potentially compromising system integrity, confidentiality, and availability.
Affected Systems
Apple macOS systems are affected, specifically those running macOS Golden Gate before version 27, macOS Sequoia before 15.8, or macOS Tahoe before 26.7. These earlier releases have not yet implemented the improved permission checks and are vulnerable to privilege escalation. Applications installed on these systems could be exploited.
Risk and Exploitability
The CVSS score of 7.8 indicates that this is a high‑severity vulnerability. The EPSS score is <1% indicating a very low likelihood of exploitation, and it is not listed in the CISA KEV catalog. Until the patch is applied, any user with access to these macOS versions could potentially gain root privileges by running a compromised app.
OpenCVE Enrichment