Impact
An Apple operating system flaw allows a crafted archive to evade the Gatekeeper quarantine workflow, enabling the execution of files that would otherwise be blocked. The vulnerability is mitigated in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, and watchOS 27. By bypassing quarantine, a malicious archive can drop and run binaries with the privileges of the user, potentially leading to full system compromise if the user has elevated rights.
Affected Systems
Apple iOS and iPadOS versions prior to 26.7 and 27, macOS Golden Gate versions prior to 27, macOS Sequoia prior to 15.8, macOS Tahoe prior to 26.7, visionOS prior to 27, and watchOS prior to 27 are affected by the flaw.
Risk and Exploitability
The EPSS score of < 1% indicates a very low but nonzero probability of exploitation and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a user opening or extracting a malicious archive; based on the description, it is inferred that an attacker would need to deliver the archive from sources such as email, the App Store, or a web download. If the user follows the necessary steps, the attacker could execute code with the user's privilege level and, in some contexts, gain elevated privileges during installation.
OpenCVE Enrichment