CVE-2025-24242

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app with root privileges may be able to access private information.
References
Link Resource
https://support.apple.com/en-us/122373 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

04 Apr 2025, 17:13

Type Values Removed Values Added
First Time Apple macos
Apple
Summary
  • (es) Este problema se solucionó mejorando la gestión de enlaces simbólicos. Este problema se solucionó en macOS Sequoia 15.4. Una aplicación con privilegios de root podría acceder a información privada.
References () https://support.apple.com/en-us/122373 - () https://support.apple.com/en-us/122373 - Vendor Advisory
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

01 Apr 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 4.4
CWE CWE-200 CWE-59

01 Apr 2025, 05:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-200

31 Mar 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 23:15

Updated : 2025-04-04 17:13


NVD link : CVE-2025-24242

Mitre link : CVE-2025-24242

CVE.ORG link : CVE-2025-24242


JSON object : View

Products Affected

apple

  • macos
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')