Executive brief
A vulnerability in the macOS PackageKit component could allow a user who already has administrative (root) access to delete protected system files. PackageKit is the system framework responsible for installing and managing software packages. While the attacker already needs high-level access to exploit this, it allows them to bypass system protections that normally prevent the modification or deletion of critical operating system files, potentially leading to system instability or the removal of security controls.
Technical details
An improper privilege management vulnerability (CWE-269) exists in the macOS PackageKit framework due to flawed state management. An attacker who has already obtained root privileges can exploit this issue to delete files that are otherwise protected by system-level integrity controls. The vulnerability was addressed by improving state management logic within the component. This issue affects macOS Sequoia versions prior to 15.7.4, macOS Sonoma versions prior to 14.8.4, and macOS Tahoe versions prior to 26. Exploitation requires local access with high privileges (PR:H).
Affected products
- Apple macOS Sequoia Before 15.7.4
- Apple macOS Sonoma Before 14.8.4
- Apple macOS Tahoe Before 26
Timeline
- 2025-09-15: patched: Initial fix in macOS Tahoe 26
- 2026-02-11: disclosed: CVE published and patched in Sequoia and Sonoma