PT-2025-5290 · Apple · Macos Sequoia+3

Published

2025-01-27

·

Updated

2025-01-29

·

CVE-2025-24115

CVSS v3.1

6.3

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions macOS Ventura versions prior to 13.7.3 macOS Sequoia versions prior to 15.3 macOS Sonoma versions prior to 14.7.3
Description A path handling issue was addressed with improved validation, allowing an app to potentially read files outside of its sandbox. The issue is related to a buffer overflow in memory, which can be exploited to read arbitrary files.
Recommendations For macOS Ventura versions prior to 13.7.3, update to version 13.7.3 to resolve the issue. For macOS Sequoia versions prior to 15.3, update to version 15.3 to resolve the issue. For macOS Sonoma versions prior to 14.7.3, update to version 14.7.3 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2025-01390
CVE-2025-24115

Affected Products

Apple Macos
Macos Sequoia
Macos Sonoma
Macos Ventura