Physical Access Vulnerability in MacOS Sequoia Affecting Security Management
CVE-2024-44231

4.6MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
20 December 2024

What is CVE-2024-44231?

CVE-2024-44231 is a high-severity vulnerability affecting macOS Sequoia 15.1 that arises when an attacker with physical access attempts to bypass the system's Login Window during a software update process. The flaw exists due to inadequate state management during software updates, which could potentially allow an unauthorized user to access sensitive information or perform unauthorized actions. Apple has issued a fix in version 15.1 to mitigate this issue. It is critical for users to ensure their systems are updated to safeguard against this vulnerability.

Affected Version(s)

macOS < 15.1

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-44231 : Physical Access Vulnerability in MacOS Sequoia Affecting Security Management