First published: Mon Jan 27 2025(Updated: )
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sonoma 14.7.3. An app may be able to access removable volumes without user consent.
Credit: product-security@apple.com Wang Yu CyberservalKirin @Pwnrin Google Threat Analysis Group Desmond Trend Micro Zero Day InitiativePwn2car & Rotiple(HyeongSeok Jang) Trend Micro Zero Day InitiativeArsenii Kostromin (0x3c3e) Joshua Jones DongJun Kim @smlijun JongSeong Kim in Enki WhiteHat @nevul37 D4m0n Joseph Ravichandran @0xjprx MIT CSAILpattern-f @pattern_F_ an anonymous researcher 云散 Mickey Jin @patch1t Pedro Tôrres @t0rr3sp3dr0 神罚 @Pwnrin Anonymous Trend Micro Zero Day InitiativeYiğit Can YILMAZ @yilmazcanyigit Michael DePlante @izobashi Trend Micro Zero Day InitiativeZhongquan Li @Guluisacat Hossein Lotfi @hosselot Trend Micro Zero Day InitiativeRodolphe BRUNETTI @eisw0lf Lupus NovaJonathan Bar Or @yo_yo_yo_jbo MicrosoftYann GASCUEL Alter SolutionsAdam M. PixiePoint Security Minghao Lin @Y1nKoc Zhejiang Universitybabywu Zhejiang University Zhejiang UniversityXingwei Lin Zhejiang UniversityCertiK SkyFall Team Bohdan Stasiuk @Bohdan_Stasiuk Uri Katz (Oligo Security)
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <14.7.3 | 14.7.3 |
macOS Ventura | <13.7.3 | 13.7.3 |
macOS Ventura | ||
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-24093 is a permissions issue that allows apps to access removable volumes without user consent.
To fix CVE-2025-24093, update to macOS Ventura version 13.7.3 or macOS Sonoma version 14.7.3.
CVE-2025-24093 affects macOS Ventura and macOS Sonoma prior to versions 13.7.3 and 14.7.3 respectively.
CVE-2025-24093 is characterized as a permissions issue combined with a type confusion vulnerability.
No, CVE-2025-24093 allows apps to access removable volumes without user consent.