Impact
A flaw in Apple macOS allows an application representing is rooted in improper privilege enforcement, enabling a process running with lower privileges to elevate itself to system level. Consequently, a malicious or compromised application could compromise device integrity and confidentiality.
Affected Systems
Affected Apple macOS platforms include macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. The description indicates the vulnerability is fixed in these releases; any devices running earlier macOS versions are at risk.
Risk and Exploitability
The CVSS score of 7.8 reflects a high impact severity, yet the EPSS score of less than 1% shows a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly stated; however, the nature of the flaw suggests that an application with sufficient local access could exploit it. Overall, the risk remains moderate due to the severe impact but low exploitation likelihood.
OpenCVE Enrichment