File Quarantine Bypass in Apple macOS Products
CVE-2025-31189

8.2HIGH

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
29 May 2025

What is CVE-2025-31189?

This vulnerability allows malicious applications to escape their sandbox environment, potentially leading to unauthorized access to sensitive system resources. Apple has resolved this issue in specific macOS updates, reinforcing the importance of maintaining up-to-date software to safeguard against such security risks. Users are encouraged to upgrade to the latest supported versions to mitigate exposure.

Affected Version(s)

macOS < 15.4

macOS < 14.7

macOS < 13.7

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.