Impact
The vulnerability is a validation issue in macOS entitlement verification that allows a malicious application to bypass sandbox restrictions and access system resources it should not control. This flaw enables an attacker to gain unauthorized access to protected files, processes, and services, compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
Apple macOS is affected. The issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. All earlier releases of these macOS lines remain vulnerable.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the flaw provides a high‑ app on the target device. Attackers would typically need local code execution or a user to run a malicious application. No publicly known exploit exists at the time of this advisory, but the severity of a successful exploit is high due to full sandbox escape potential.
OpenCVE Enrichment