Apple PackageKit Directory Path Validation Vulnerability Granting Root Privileges

Vulnerability

A vulnerability in the PackageKit component of macOS can allow an application to gain root privileges. This issue arises from a parsing problem in how directory paths are handled, which has been addressed in the latest macOS updates.

Impact

Exploitation of this vulnerability can lead to unauthorized root access on the affected system.

Remediation

Users can update to macOS Sequoia 15.7, macOS Sonoma 14.8, or macOS Tahoe 26 to address this vulnerability.

Added: Sep 16, 2025, 12:32 AM
Updated: Sep 16, 2025, 12:32 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
3.3
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.