Impact
The vulnerability arises from missing entitlement checks that allow a malicious application to perform actions normally restricted to privileged system processes, resulting in the potential acquisition of root with CWE‑280. An app can deliberately exploit these checks to elevate its privileges to system level, compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
Apple macOS is affected by this flaw; it was resolved in macOS Golden Gate 27. All versions earlier than Golden Gate 27 are vulnerable. The issue affects the entire operating system as it permits unauthorized privilege elevation.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity of potential impact. The EPSS score suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local execution of a malicious application, as the flaw requires the ability to launch an app with certain entitlements. An attacker who can run code on the system can abuse the missing checks to gain root privileges, which considerably increases the risk of a full system compromise.
OpenCVE Enrichment