Impact
This issue stems from the operating system’s handling of symbolic links, allowing a sandboxed application to resolve links that point to protected system files or directories. The result is a privilege‑escalation flaw that lets the app exceed its sandboxed boundaries. This vulnerability is an example of CWE-59, in which symbolic‑link abuse allows the resolution of paths that should be inaccessible.
Affected Systems
Apple macOS installations that have not yet been updated to macOS Golden Gate 27 or later are affected. The flaw was fixed in that release, so any version older than 27 remains susceptible for applications that create or interact with symbolic links.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, yet the risk is substantial because sandbox breakout can grant local processes higher privileges. The CVSS score of 8.4 indicates a high severity vulnerability. The likely attack vector is local; an attacker must be able to influence the symlink a sandboxed application resolves, perhaps by placing a malicious link in a location the app accesses. If such a link is crafted, the application can access files or directories outside its sandbox, compromising confidentiality or integrity of protected system resources.
OpenCVE Enrichment