CVE-2025-24103

Published Jan 27, 2025

Last updated 6 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-24103 is a security vulnerability affecting Apple's macOS operating system. Disclosed on January 27, 2025, it impacts versions such as Ventura 13.7.3, Sequoia 15.3, and Sonoma 14.7.3. The vulnerability lies in the Security component of macOS and results from inadequate validation of symlinks. The flaw can be exploited by a malicious application to gain unauthorized access to protected user data, potentially compromising user privacy and data confidentiality. Apple addressed this vulnerability by improving symlink validation in security updates released on January 27, 2025. Users are advised to update their macOS to the patched versions: Ventura 13.7.3, Sequoia 15.3, or Sonoma 14.7.3.

Description
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to access protected user data.
Source
product-security@apple.com
NVD status
Modified
Products
macos

Risk scores

CVSS 3.1

Type
Primary
Base score
5.5
Impact score
3.6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

nvd@nist.gov
CWE-59
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-59

Social media

Hype score
Not currently trending

Configurations