Impact
A use‑after‑free flaw in macOS execution with kernel privileges. If an attacker can control the payload, arbitrary code runs with the highest operating‑system rights, enabling full system compromise.
Affected Systems
Apple macOS versions prior to macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are affected. The issue was fixed in those releases, so systems running earlier macOS versions remain vulnerable.
Risk and Exploitability
The flaw achieves native code execution at the kernel level, representing the highest possible impact. No public exploitation data is currently available (EPSS score < 1%, KEV not listed), but the severity inferred from the CVSS and the nature of kernel privilege escalation suggests a high to critical risk. Likely attackers have local application execution privileges and can exploit the flaw via a malicious app or a crafted input that leads to the use‑after‑free condition.
OpenCVE Enrichment