Impact
A logic issue was identified in macOS that could allow a malicious or compromised application to escape its sandbox boundaries, potentially compromising the integrity or confidentiality of system resources. The issue was addressed with improved checks in macOS Golden Gate 27. An attacker could utilize the deficient logic to breach the security confinement of a sandboxed application.
Affected Systems
The vulnerability affects Apple macOS versions prior to macOS Golden Gate 27. No specific build numbers are listed, but any macOS release before the Golden Gate fix 27.
Risk and Exploitability
The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 7.5 indicates a moderate severity. Because the flaw allows an application to escape its sandbox, the potential impact includes unauthorized access to system resources. The likely attack vector is local, requiring that the attacker run or influence the target application. The vulnerability would only be exploitable by an application that can be executed on the vulnerable system.
OpenCVE Enrichment