CVE-2025-24249
- EPSS 0.07%
- Published 31.03.2025 23:15:22
- Last modified 07.04.2025 13:36:31
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to check the existence of an arbitrary path on the file system.
CVE-2025-24250
- EPSS 0.06%
- Published 31.03.2025 23:15:22
- Last modified 07.04.2025 13:36:17
This issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app acting as a HTTPS proxy could get access to sensitive user data.
CVE-2025-24253
- EPSS 0.06%
- Published 31.03.2025 23:15:22
- Last modified 07.04.2025 13:36:08
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.
CVE-2025-24254
- EPSS 0.06%
- Published 31.03.2025 23:15:22
- Last modified 07.04.2025 13:35:54
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A user may be able to elevate privileges.
CVE-2025-24255
- EPSS 0.03%
- Published 31.03.2025 23:15:22
- Last modified 07.04.2025 13:35:42
A file access issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.
CVE-2025-24256
- EPSS 0.06%
- Published 31.03.2025 23:15:22
- Last modified 07.04.2025 13:35:34
The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to disclose kernel memory.
CVE-2025-24257
- EPSS 0.01%
- Published 31.03.2025 23:15:22
- Last modified 07.04.2025 13:35:26
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to cause unexpected system termination or write kernel memory.
CVE-2025-24259
- EPSS 0.06%
- Published 31.03.2025 23:15:22
- Last modified 07.04.2025 13:35:15
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.
CVE-2025-24260
- EPSS 0.06%
- Published 31.03.2025 23:15:22
- Last modified 07.04.2025 13:34:55
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker in a privileged position may be able to perform a denial-of-service.
CVE-2025-24238
- EPSS 0.1%
- Published 31.03.2025 23:15:21
- Last modified 04.04.2025 17:12:14
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain elevated privileges.