Impact
A permissions flaw in macOS allows an application to bypass Apple Intelligence security prompts, potentially granting elevated privileges or access without user awareness. This weakness can enable an attacker to perform unauthorized actions under the guise of legitimate software permissions, compromising confidentiality and integrity of user data. The vulnerability is tied to improper authorization control.
Affected Systems
Apple macOS versions before Golden Gate 27 are affected. The fix is included in macOS Golden Gate 27, so any macOS installation earlier than 27 requires an update to mitigate the flaw.
Risk and Exploitability
The CVSS score is 5.5, indicating a medium severity, while the EPSS score of <1% indicates a very low likelihood of exploitation, suggesting a low overall risk. Based on the description, the likely attack vector involves an app exploiting the permission error to manipulate prompt handling, which could be initiated from a local user context or a compromised application. The vulnerability is not listed in the CISA KEV catalog, but the presence of a bypass indicates a potential for misuse if exploited.
OpenCVE Enrichment