CVE-2025-24170

Published Mar 31, 2025

Last updated 5 days ago

CVSS high 7.8
Apple
macOS

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-24170 refers to a logic issue that was resolved through improved file handling. The vulnerability affects macOS Ventura 13.7.5 and macOS Sonoma 14.7.5. Successful exploitation of this vulnerability could allow an application to gain root privileges.

Description
A logic issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sonoma 14.7.5. An app may be able to gain root privileges.
Source
product-security@apple.com
NVD status
Modified
Products
macos

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-276

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

15

Configurations