CVE-2025-24236

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.
References
Link Resource
https://support.apple.com/en-us/122373 Vendor Advisory Release Notes
https://support.apple.com/en-us/122374 Vendor Advisory Release Notes
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

04 Apr 2025, 17:11

Type Values Removed Values Added
References () https://support.apple.com/en-us/122373 - () https://support.apple.com/en-us/122373 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/122374 - () https://support.apple.com/en-us/122374 - Vendor Advisory, Release Notes
First Time Apple macos
Apple
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

02 Apr 2025, 16:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
Summary
  • (es) Se solucionó un problema de acceso con restricciones adicionales en el entorno aislado. Este problema se solucionó en macOS Sequoia 15.4 y macOS Sonoma 14.7.5. Una aplicación podría acceder a datos confidenciales del usuario.
CWE CWE-284

31 Mar 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 23:15

Updated : 2025-04-04 17:11


NVD link : CVE-2025-24236

Mitre link : CVE-2025-24236

CVE.ORG link : CVE-2025-24236


JSON object : View

Products Affected

apple

  • macos
CWE
CWE-284

Improper Access Control