PT-2025-3037 · Apple · Apple Macos

0X3C3E

+1

·

Published

2024-12-11

·

Updated

2025-01-31

·

CVE-2024-54516

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions macOS versions prior to 14.7.2 macOS versions prior to 15.2
Description A permissions issue was addressed with additional restrictions. This issue may allow an app to approve a launch daemon without user consent. The problem is related to incorrect permission storage in the SharedFileList component of macOS, which could allow an attacker to impact the integrity of protected information.
Recommendations For macOS versions prior to 14.7.2, update to macOS Sonoma 14.7.2 to resolve the issue. For macOS versions prior to 15.2, update to macOS Sequoia 15.2 to resolve the issue. As a temporary workaround, consider restricting the approval of launch daemons to minimize the risk of exploitation.

Fix

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01501
CVE-2024-54516

Affected Products

Apple Macos