PT-2025-13924 · Apple · Apple Macos
Published
2025-03-31
·
Updated
2025-04-04
·
CVE-2025-24242
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
macOS versions prior to 15.4
Description
The issue allows an app with root privileges to potentially access private information due to improper handling of symlinks. This has been addressed with improved handling of symlinks.
Recommendations
For versions prior to 15.4, update to macOS Sequoia 15.4 to resolve the issue.
Fix
LPE
Information Disclosure
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apple Macos