Impact
An application circumventing macOS Gatekeeper removes the code‑signing verification that normally blocks unsigned or improperly signed software. The flaw is an improper access control that lets an authorized program override the security check, enabling malicious code to run without user consent.
Affected Systems
macOS releases older than Golden Gate 27 are vulnerable. The issue was fixed in macOS Golden Gate 27 by Apple, so any system running earlier versions may still be at risk if Gatekeeper is not correctly enforced.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, indicating a very low likelihood of exploitation at present. The CVSS score of 4.4 indicates a moderate severity. Nevertheless, the impact of successful bypass is the execution of unsigned code, which could lead to full system compromise if malware is launched. Exploitation would require delivery of a malicious application that evades the check; once executed, it would run with the user’s privileges. Upgrading to macOS Golden Gate 27 or applying the vendor patch removes the flaw entirely.
OpenCVE Enrichment