This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An application may be able to gain elevated privileges.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon