CVE-2025-24236

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.
References
Link Resource
https://support.apple.com/en-us/122373 Vendor Advisory Release Notes
https://support.apple.com/en-us/122374 Vendor Advisory Release Notes
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

04 Apr 2025, 17:11

Type Values Removed Values Added
References () https://support.apple.com/en-us/122373 - () https://support.apple.com/en-us/122373 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/122374 - () https://support.apple.com/en-us/122374 - Vendor Advisory, Release Notes
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
First Time Apple macos
Apple

02 Apr 2025, 16:17

Type Values Removed Values Added
Summary
  • (es) Se solucionó un problema de acceso con restricciones adicionales en el entorno aislado. Este problema se solucionó en macOS Sequoia 15.4 y macOS Sonoma 14.7.5. Una aplicación podría acceder a datos confidenciales del usuario.
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

31 Mar 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 23:15

Updated : 2025-04-04 17:11


NVD link : CVE-2025-24236

Mitre link : CVE-2025-24236

CVE.ORG link : CVE-2025-24236


JSON object : View

Products Affected

apple

  • macos
CWE
CWE-284

Improper Access Control