PT-2024-10291 · Apple · Apple Macos

Jonathan Bar Or

+3

·

Published

2024-12-11

·

Updated

2026-01-12

·

CVE-2024-44243

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions macOS versions prior to 15.2
Description The issue is related to a configuration problem that has been addressed with additional restrictions. It allows an app to modify protected parts of the file system. The vulnerability can be exploited by local attackers with root privileges and user interaction, potentially leading to the installation of malicious kernel drivers, rootkits, or other persistent malware. The vulnerability is related to the Storage Kit component, which is responsible for maintaining disk state, and it can be exploited by loading third-party kernel extensions, bypassing System Integrity Protection (SIP).
Recommendations To resolve the issue, update to macOS Sequoia 15.2 or later. As a temporary workaround, consider restricting access to the Storage Kit component or disabling the loading of third-party kernel extensions until a patch is available. Additionally, users should be cautious when interacting with applications that require root privileges, as this could potentially lead to exploitation of the vulnerability.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-00706
CVE-2024-44243

Affected Products

Apple Macos