Impact
The vulnerability permits a local application to bypass permission checks, enabling the app stems from a permission check failure and could allow an attacker to modify system files, install malware, or compromise the entire machine. The impact includes loss of confidentiality, integrity, and availability of the affected macOS system. The likely attack vector is local execution of a malicious application, inferred from the description that an app may be able to gain root privileges.
Affected Systems
Apple macOS; specifically macOS Golden Gate versions prior to 27, macOS Sequoia versions prior to 15.8, and macOS Tahoe versions prior to 26.7.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploits yet. Attackers would need local access to a vulnerable application; this inference is drawn from the description that an app may be able to gain root privileges.
OpenCVE Enrichment