A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileges.
The problem results from improper state management (logic issue), partially classified as CWE-281 (improper behavior during privilege change). A malicious or compromised application can exploit this error to obtain higher system privileges than granted. Apple fixed the vulnerability by improving state management mechanisms in the system.
An attacker controlling an application running on the vulnerable system can obtain elevated privileges, potentially allowing complete system takeover, breach of confidentiality, integrity, and data availability.
The system should be updated to macOS Sequoia 15.2 or newer. Patch is available through Apple's system update mechanism and at https://support.apple.com/en-us/121839
Apple macOS Sequoia in versions prior to 15.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApple macOS
OSApple< 15.2
Related vulnerabilities
Pominięcie uwierzytelniania w Screen Sharing na macOS
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
Apple — memory corruption (RCE) w przetwarzaniu strumieni audio
Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach