PT-2024-31012 · Apple · Apple Macos
Mickey Jin
·
Published
2024-09-16
·
Updated
2025-03-15
·
CVE-2024-44178
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
macOS versions prior to 13.7
macOS Sonoma versions prior to 14.7
macOS Sequoia versions prior to 15
Description
The issue allows an app to modify protected parts of the file system due to a symlink validation bypass. This was addressed with improved validation of symlinks.
Recommendations
For macOS versions prior to 13.7, update to macOS Ventura 13.7 to resolve the issue.
For macOS Sonoma versions prior to 14.7, update to macOS Sonoma 14.7 to resolve the issue.
For macOS Sequoia versions prior to 15, update to macOS Sequoia 15 to resolve the issue.
Fix
Memory Corruption
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apple Macos