Impact
The issue is an out‑of‑bounds write that allows a malicious application to write beyond buffer limits. This flaw can be leveraged to gain root privileges on affected macOS systems. If successful, an attacker could modify system files, install persistence mechanisms, and compromise confidentiality, integrity, and availability.
Affected Systems
Apple macOS products are impacted. The vulnerability is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Systems running these releases or later are safe.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of < 1 % shows a very low yet measurable exploitation probability. This flaw is not listed in the CISA KEV catalog, so there are no reported active attacks. The likely attack vector is local, where an attacker can execute or install a malicious application containing the vulnerable code. Privilege escalation would require the vulnerable code to run with unprivileged privileges, after which the out‑of‑bounds write can elevate the process to system level.
OpenCVE Enrichment