Impact
A path handling flaw in paths in a way that the operating system interprets as higher privilege access. The weakness is a CWE‑22 (Path Traversal) defect that permits an application to override intended permissions, enabling the process to perform privileged operations, modify system files, or access restricted data. This can result in the attacker gaining full administrative control over the affected machine.
Affected Systems
Apple macOS versions Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 are affected. All other releases are not impacted according to the vendor advisory.
Risk and Exploitability
The CVSS score of 7.8 categorizes the vulnerability as High. The EPSS score is < 1 % and the flaw is not listed in CISA KEV, indicating low exploitation probability. The attack likely requires a local, authenticated user to run a crafted application that leverages the path handling defect, after which the application can elevate itself to higher privileges. A remote exploit would need to deliver such a malicious application, for example via phishing or a malicious download, making local execution the primary vector.
OpenCVE Enrichment