Impact
An authentication flaw in macOS permits a malicious or vulnerable application to trigger unexpected system termination, effectively taking the operating system offline. This improper authentication weakness (CWE‑287) results in a denial of service.
Affected Systems
Apple macOS releases earlier than macOS Golden Gate 27, Sequoia 15.8, or Tahoe 26.6 are affected. These versions lack the improved authentication routine that was introduced in the specified fix releases, so any system running those earlier is susceptible to the termination flaw.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score (< 1 %) and absence from the CISA KEV catalog suggest a low probability of active exploitation at present. The exploit appears to require a local application or privileged process that can trigger the flawed authentication routine; no documented remote attack vector exists.
OpenCVE Enrichment