Impact
Apple’s macOS Gatekeeper subsystem contains a logic flaw in its state management that can be exploited to bypass authorization checks. An attacker can forge or manipulate the state so that an unsigned or otherwise prohibited application is treated as compliant, allowing it to run with the privileges of the user who launches it and paving the way for further compromise. This weakness is identified as CWE‑693, improper control of a returned value.
Affected Systems
The flaw exists in macOS releases prior to the updates that contain the fix. Users running macOS Golden Gate earlier than version 27, macOS Sequoia prior to 15.8, and macOS Tahoe before 26.7 are affected. All newer releases that include the correction are not vulnerable.
Risk and Exploitability
The CVSS score of 5.5 signals moderate severity while the EPSS score of < 1 % indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Gatekeeper operates as a local security policy, so the most likely attack vector is a local user installing or executing a malicious application that takes advantage of the logic flaw. Remote exploitation without user interaction is conceivable only if the attacker can deliver the compromised application via social engineering or a deceptive download. No special system privileges are required beyond those needed to run a regular application.
OpenCVE Enrichment