9.8
CVE-2025-24253 - Symlink Handling Issue Exposes Protected User Data
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.
9.8
CVE-2025-24195 - Privilege Escalation via Integer Overflow in macOS
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A user may be able to elevate privileges.
9.8
CVE-2025-24204 - macOS Vulnerability Grants Local Applications Access to Protected User Data
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
6.3
CVE-2025-24212 - Sandbox Escape via App in Apple Operating Systems
This issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.
9.8
CVE-2025-24245 - macOS Keychain Delay Bypass Exposes Saved Passwords
This issue was addressed by adding a delay between verification code attempts. This issue is fixed in macOS Sequoia 15.4. A malicious app may be able to access a user's saved passwords.
9.8
CVE-2025-31183 - Unrestricted Data Container Access Allowing App to Read Sensitive User Data
The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.
5.5
CVE-2025-30454 - Path Handling Issue Allowing Malicious App to Access Private Information
A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. A malicious app may be able to access private information.
9.8
CVE-2025-24250 - Sensitive Data Exposure via Malicious HTTPS Proxy
This issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app acting as a HTTPS proxy could get access to sensitive user data.
8.8
CVE-2025-24196 - Type Confusion Allows Kernel Memory Read in macOS
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker with user privileges may be able to read kernel memory.
9.8
CVE-2025-24207 - iCloud Storage Enablement Without Consent via macOS Permissions Flaw
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to enable iCloud storage features without user consent.