Impact
A permissions issue was addressed with improved path validation. The flaw allows a local application to modify protected system files, potentially overwriting critical binaries or configuration files. Such manipulation could enable persistence, denial of service, or further compromise of the operating system.
Affected Systems
Affected Apple products include iOS 27 and iPadOS 27; macOS Golden Gate 27, macOS Sequoia 15.8 and macOS Tahoe 26.7; tvOS 27, visionOS 27, and watchOS 27. Devices running any of these versions are susceptible.
Risk and Exploitability
The vulnerability is a local privilege escalation that can be exploited by any app installed on the device, ensuring the attack vector is local and requires no remote network conditions. The CVSS score is 9.8, and the EPSS score indicates a very low likelihood of exploitation (< 1%). The flaw is not listed in CISA KEV. Because the attack requires a malicious app or an app supplied by a compromised developer, the exploitation likelihood depends on the prevalence of vulnerable OS versions and the use of trusted applications. The potential impact remains significant until the devices are updated to the patched releases.
OpenCVE Enrichment