Home

Description

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.

PUBLISHED Reserved 2025-01-17 | Published 2025-03-31 | Updated 2025-11-03 | Assigner apple

Problem types

An app may be able to access protected user data

Product status

Any version before 15.4
affected

Any version before 14.7
affected

Any version before 13.7
affected

References

seclists.org/fulldisclosure/2025/Apr/10

seclists.org/fulldisclosure/2025/Apr/9

seclists.org/fulldisclosure/2025/Apr/8

support.apple.com/en-us/122373

support.apple.com/en-us/122374

support.apple.com/en-us/122375

cve.org (CVE-2025-24278)

nvd.nist.gov (CVE-2025-24278)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.