6.5
CVE-2025-24239 - App Access to Protected User Data via Downgrade Issue
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
5.5
CVE-2025-31191 -
This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.
9.8
CVE-2025-24238 - Privilege Escalation via Logic Error in Apple OS Components
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. An app may be able to gain elevated privileges.
5.5
CVE-2025-30447 - Logging Sanitization Flaw Allowing Access to Sensitive User Data
The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.
5.5
CVE-2025-24280 - App May Gain Unauthorized Access to User Sensitive Data in macOS
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.
4.3
CVE-2025-24279 - macOS File Handling Vulnerability Allows Unprivileged App to Read User Contacts
This issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access contacts.
5.5
CVE-2025-30451 - macOS Redaction Bug Exposing Sensitive User Data
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.
8.4
CVE-2025-24255 - macOS Sandbox Escape via Improper File Access Validation
A file access issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to break out of its sandbox.
2.4
CVE-2025-24193 - Limited Access to Photos via USBโC on Unlocked Devices in iOS/iPadOS
This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker with a USB-C connection to an unlocked device may be able to programmatically access photos.
5.5
CVE-2025-24202 - Sensitive Data Exposure via Improper Logging in Apple Operating Systems
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.