Impact
A permissions flaw in Apple macOS allows an application to access local network devices without receiving explicit user consent. The flaw arose from insufficient state management that failed to enforce proper access controls, enabling unauthorized network interaction. This can expose sensitive device information or allow control of modern networking equipment, potentially compromising the confidentiality and integrity of the local network.
Affected Systems
Apple macOS before version 27 (Golden Gate) is affected. Any macOS installation that has not been updated to Golden Gate 27 or later may allow a malicious or untrusted application to exploit the permissions issue.
Risk and Exploitability
A CVSS score of 5.5 indicates moderate severity, and the EPSS score of < 1% shows a very low exploitation probability. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker might distribute a malicious macOS application that, once installed, can scan or communicate with local network devices without the user's knowledge, because the flaw involves insufficient state management of network permissions. This inference assumes that the attacker can provide a user‑installed app. The potential impact is that unauthorized network access could be achieved across the local environment.
OpenCVE Enrichment