Impact
A logic flaw in macOS can allow any application to bypass Gatekeeper verification, enabling the execution of unsigned or other restricted code. The issue stems from an improvement in state management that, while designed to fix a problem, inadvertently allowed applications to falsify Gatekeeper checks. The result is that an application could be executed without the security guarantees normally provided by Gatekeeper. This flaw is identified as affecting application integrity and, to the extent Gatekeeper is relied upon, system integrity as well. description states that an app may be able to bypass Gatekeeper checks, but the exact mechanism for how the logic flaw is triggered is not detailed in the CVE. Thus, while the impact is a Gatekeeper bypass, the specific steps an attacker would need to take are inferred rather than documented.
Affected Systems
Apple’s macOS platform is impacted; all macOS releases prior to the Golden Gate 27 update may allow a Gatekeeper bypass. The vulnerability is present in the operating system irrespective of user profile or additional configuration, as Gatekeeper operates at the OS state‑management layer. Users running earlier macOS versions are potentially susceptible. The CVE description does not specify exact sub‑versions or hardware platforms, so the scope remains broad. Based on the information provided, it is inferred that the vulnerability is not limited to any specific user roles or settings.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, while the EPSS score of less than 1% signals a very low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting no large‑scale exploitation has been observed to date. The flaw could be triggered by any mechanism that enables an application's execution without Gatekeeper verification, but specific exploit conditions or attack vectors are not disclosed in the available data. Based on the description, it is inferred that the likely attack vector involves an application attempting to execute code that bypasses Gatekeeper checks, though no explicit exploit code or technique is disclosed. The lack of detailed attack vector information represents a knowledge gap.
OpenCVE Enrichment