PT-2025-3037 · Apple · Apple Macos
0X3C3E
+1
·
Published
2024-12-11
·
Updated
2025-01-31
·
CVE-2024-54516
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
macOS versions prior to 14.7.2
macOS versions prior to 15.2
Description
A permissions issue was addressed with additional restrictions. This issue may allow an app to approve a launch daemon without user consent. The problem is related to incorrect permission storage in the SharedFileList component of macOS, which could allow an attacker to impact the integrity of protected information.
Recommendations
For macOS versions prior to 14.7.2, update to macOS Sonoma 14.7.2 to resolve the issue.
For macOS versions prior to 15.2, update to macOS Sequoia 15.2 to resolve the issue.
As a temporary workaround, consider restricting the approval of launch daemons to minimize the risk of exploitation.
Fix
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos