Impact
A flaw in macOS’s certificate validation process can allow an attacker positioned on a privileged network segment to bypass authentication checks and intercept SSL/TLS traffic, effectively performing a man‑in‑the‑middle. This weakness is a direct implication of improper certificate validation (CWE‑295) and enables the attacker to read or tamper with confidential data transmitted over the network.
Affected Systems
Apple’s macOS in the Golden Gate series up to 26 to 15.7, and Tahoe up to 26.6 are affected. The vulnerability is resolved in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Risk and Exploitability
The attacker must already have a privileged position on the network to exploit this flaw. No CVSS score is available, and the EPSS score is not provided, indicating no publicly reported data on the likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. However, once the condition of a privileged network segment is met, the attack can be carried out with a simple certificate spoofing technique, underscoring the potential for high impact data compromise.
OpenCVE Enrichment