Impact
The CVE describes a permissions issue that allows a malicious application to break out of its sandbox confinement, potentially undermining the isolation guarantees provided by macOS, iOS, and iPadOS.
Affected Systems
Apple's macOS operating system is affected. Versions of macOS Sequoia, Sonoma, and Tahoe that precede 15.7.8, 14.8.8, and 26.6 respectively remain vulnerable, while the patched releases 15.7.8, 14.8.8, and 26.6 contain the fix. The same vulnerability also applies to iOS and iPadOS. Versions prior to iOS 18.7.10 and iPadOS 18.7.10 are vulnerable.
Risk and Exploitability
The CVSS score of 9.8 highlights a critical severity, but the EPSS below 1% suggests only a low probability of active exploitation in the wild. The vulnerability is not listed in CISA KEV. Based on the description, a malicious application that obtains elevated permissions can potentially escape its sandbox, indicating a local attack vector that requires the attacker to run a compromised app on the target machine. No publicly disclosed exploit code is available, so the risk hinges on the likelihood of such an app being installed.
OpenCVE Enrichment