PT-2025-5311 · Apple · Macos Sequoia+1
0X3C3E
+4
·
Published
2025-01-17
·
Updated
2025-01-30
·
CVE-2025-24140
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
macOS Sequoia versions prior to 15.3
Description
The issue was addressed through improved state management. It is related to errors in using standard permissions in the iCloud service for macOS, which could allow a remote attacker to execute arbitrary code. Files downloaded from the internet may not have the quarantine flag applied.
Recommendations
For versions prior to 15.3, update to macOS Sequoia 15.3 to resolve the issue. As a temporary workaround, consider applying the quarantine flag to files downloaded from the internet manually until the update is applied.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apple Macos
Macos Sequoia