Impact
A validation flaw exists in macOS entitlement verification that allows a malicious application to bypass sandbox restrictions and access system resources it should not be able to reach. The flaw can lead to unauthorized reading or modification of protected files, processes, or services, threatening confidentiality, integrity, and system availability.
Affected Systems
Apple macOS is the affected vendor. The issue is addressed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk. The EPSS score is reported as < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers would typically need to run a malicious application on the target system to exploit this flaw.
OpenCVE Enrichment