Logic Issue in macOS Ventura and Sonoma Allowing Elevated Access
CVE-2025-24170

7.8HIGH

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
31 March 2025

Summary

A logic issue in macOS Ventura and Sonoma has been identified, which involves improper file handling potentially allowing unauthorized applications to gain root privileges. This could expose users to security risks, as malicious software might exploit this flaw to execute sensitive operations without appropriate permissions. The issue has been addressed in updates for both macOS Ventura and Sonoma, ensuring enhanced security for users who install the latest versions.

Affected Version(s)

macOS < 14.7

macOS < 13.7

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.