PT-2025-13924 · Apple · Apple Macos

Published

2025-03-31

·

Updated

2025-04-04

·

CVE-2025-24242

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions macOS versions prior to 15.4
Description The issue allows an app with root privileges to potentially access private information due to improper handling of symlinks. This has been addressed with improved handling of symlinks.
Recommendations For versions prior to 15.4, update to macOS Sequoia 15.4 to resolve the issue.

Fix

LPE

Information Disclosure

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-24242

Affected Products

Apple Macos