Impact
A flaw in macOS’s certificate validation process allows an attacker positioned on a privileged network segment to intercept network traffic. This vulnerability is a certificate validation error (CWE-295) that jeopardizes confidentiality.
Affected Systems
Apple’s macOS in the Golden Gate series before version 27, Sequoia before 15.8, and Tahoe before 26.7 are affected. The issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 and later releases.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while the EPSS score of less than 1% signals a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to already have a privileged position on the network; once that condition is met, the attacker may intercept traffic, underscoring the potential for confidential data compromise.
OpenCVE Enrichment