Impact
The vulnerability originates from missing entitlement checks and missing authorization in macOS, allowing a non‑privileged application to modify protected parts of the file system. This represents a weakness identified as CWE‑862. The ability to alter system files compromises integrity and may enable further malicious actions.
Affected Systems
Apple macOS is affected in all releases prior to macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, which contain the fix for this issue. Therefore any older macOS version before those releases remains vulnerable.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.5 indicates a moderate impact. The likely attack vector is inferred to be user‑initiated execution of a malicious or compromised application that exploits the missing entitlement checks to gain write access to protected file system locations.
OpenCVE Enrichment