PT-2024-31042 · Apple · Macos Sequoia+1

Csaba Fitzl

+2

·

Published

2024-10-28

·

Updated

2025-01-06

·

CVE-2024-44211

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions macOS Sequoia versions prior to 15.1
Description This issue was addressed with improved validation of symlinks. An app may be able to access user-sensitive data.
Recommendations For versions prior to 15.1, update to macOS Sequoia 15.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive data until the update is applied.

Fix

Improper Preservation of Permissions

Link Following

Weakness Enumeration

Related Identifiers

CVE-2024-44211

Affected Products

Apple Macos
Macos Sequoia