Permissions Issue in Apple macOS Products
CVE-2025-31261

5.5MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
29 May 2025

What is CVE-2025-31261?

A vulnerability affecting certain versions of Apple's macOS has been identified, where an application could potentially gain unauthorized access to protected user data due to insufficient sandbox restrictions. This issue has been addressed in subsequent updates, specifically in macOS Ventura 13.7.5, macOS Sequoia 15.4, and macOS Sonoma 14.7.5. Users are encouraged to update their systems to secure their sensitive information from unauthorized access.

Affected Version(s)

macOS < 15.4

macOS < 14.7

macOS < 13.7

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.