A malicious actor who has local access to the endpoint on which a macOS sensor is going to be installed, may overwrite a limited number of files with output from the sensor installation. The malicious actor would have to trick a victim to install malware in order to obtain such access. Exploitation of this issue can only occur at a specific point of time during the installation process and depends on specific conditions.
Insecure file handling
VMware Carbon Black Cloud macOS Sensor
Refer to vendor advisory for the complete list of affected products and their respective patches.