Impact
The vulnerability allows an application to escape its sandbox confinement due to insufficient enforcement checks, potentially giving the app higher privileges within the operating system. The flaw is linked to improper access control, as indicated by the associated weaknesses. As a result, an attacker could gain the ability to read or modify protected data, install persistence mechanisms, or run additional privileged code once the sandbox boundary is breached.
Affected Systems
Apple macOS releases are impacted, including earlier builds of Golden Gate, Sequoia, and Tahoe. The vulnerability is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7; any earlier versions on those macOS iterations remain vulnerable.
Risk and Exploitability
The EPSS score of < 1% indicates a very low likelihood of exploitation, and the CVE is not listed in CISA's Known Exploited Vulnerabilities catalog. The flaw involves a sandbox escape that can elevate the privileges of an application, but no documented exploit activity or widespread usage has been reported. The high impact comes from allowing a sandboxed process to run with higher OS privileges, potentially compromising system confidentiality, integrity, and availability.
OpenCVE Enrichment