PT-2025-5285 · Apple · Apple Macos

Published

2025-01-27

·

Updated

2025-01-29

·

CVE-2025-24108

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions macOS versions prior to 15.3
Description The issue is related to the insecure storage of confidential information in macOS, allowing an attacker to gain unauthorized access to protected data. An access issue was addressed with additional sandbox restrictions, which could enable an app to access protected user data.
Recommendations For macOS versions prior to 15.3, update to macOS Sequoia 15.3 to resolve the issue. As a temporary workaround, consider restricting access to sensitive data until the update is applied.

Fix

Missing Authorization

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-01388
CVE-2025-24108

Affected Products

Apple Macos