PT-2024-30974 · Apple · Apple Macos

Published

2024-09-16

·

Updated

2024-12-12

·

CVE-2024-44132

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions macOS versions prior to Sequoia 15
Description This issue allowed an app to potentially escape its sandbox due to improper handling of symlinks. The problem was addressed with improved handling of symlinks.
Recommendations For versions prior to macOS Sequoia 15, update to macOS Sequoia 15 to resolve the issue. As a temporary workaround, consider restricting the use of symlinks in sandboxed applications until a patch is available.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-44132

Affected Products

Apple Macos