Impact
The vulnerability arises from insufficient validation of file paths when extracting archives (CWE-22). A malicious archive can include paths that escape the intended extraction directory, allowing the attacker to write files to arbitrary locations. This could overwrite system binaries, configuration files, or user data, potentially leading to privilege escalation, persistence, or denial of service.
Affected Systems
Affected Apple operating systems include iOS and iPadOS versions prior to 26.7 and 27, macOS Golden Gate prior to 27, macOS Sequoia before 15.8, macOS Tahoe before 26.7, and visionOS before 27. The issue is fixed in the versions listed above.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity level. The EPSS score of < 1% shows a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via extraction of a malicious archive, which may be delivered by email attachments, downloaded files, or malicious apps. Successful exploitation would require that the archive is processed by a system component with sufficient privileges.
OpenCVE Enrichment