Impact
The vulnerability is a logic issue in Gatekeeper, Apple's binary protection system. It permits an application that would otherwise be blocked from execution to bypass Gatekeeper checks, thereby enabling the installation or launch of unsigned or otherwise untrusted software. The flaw stems from improper control over the Gatekeeper authorization process (CWE‑693). If exploited, a user could run arbitrary code from a malicious application without providing explicit consent, potentially leading to data theft, malware installation, or other integrity violations.
Affected Systems
Apple macOS systems running macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 are affected. The vulnerability is fixed in these versions and all later releases. Users of earlier or unpatched releases remain at risk until the appropriate OS update is installed.
Risk and Exploitability
Exploitation requires a local attacker to supply or otherwise install the malicious application on the target machine, indicating a local attack vector. The CVSS score of 4.4 reflects moderate severity, while the EPSS score of less than 1% shows that the probability of exploitation in the wild is very low. The vulnerability is not listed in the CISA KEV catalog. The likely vector is a compromised or malicious application that deliberately circumvents Gatekeeper during installation or launch.
OpenCVE Enrichment