Access Issue in Apple macOS Products Affecting User Privacy
CVE-2025-24116

4.4MEDIUM

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
27 January 2025

Summary

An access issue in Apple macOS products relates to additional sandbox restrictions that were not adequately enforced. This vulnerability has been fixed in recent updates; however, it was possible for certain applications to potentially bypass user privacy preferences, compromising the security and confidentiality of user data. It's crucial for users to ensure their systems are updated to the latest versions to mitigate this risk.

Affected Version(s)

macOS < 14.7

macOS < 15.3

macOS < 13.7

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.