First published: Mon Jan 27 2025(Updated: )
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to access information about a user's contacts.
Credit: product-security@apple.com Kirin @Pwnrin Bohdan Stasiuk @Bohdan_Stasiuk Mickey Jin @patch1t Minghao Lin @Y1nKoc Zhejiang Universitybabywu Zhejiang University Zhejiang UniversityXingwei Lin Zhejiang UniversityWang Yu CyberservalGoogle Threat Analysis Group Desmond Trend Micro Zero Day InitiativePwn2car & Rotiple (HyeongSeok Jang) Trend Micro Zero Day InitiativeCVE-2025-24085 Matej Moravec @MacejkoMoravec Arsenii Kostromin (0x3c3e) Joshua Jones DongJun Kim @smlijun JongSeong Kim in Enki WhiteHat @nevul37 D4m0n Joseph Ravichandran @0xjprx MIT CSAILan anonymous researcher pattern-f @pattern_F_ Michael (Biscuit) Thomas @social.lol) @biscuit 云散 Pedro Tôrres @t0rr3sp3dr0 Josh Parnham @joshparnham 神罚 @Pwnrin @RenwaX23 Michael DePlante @izobashi Trend Micro Zero Day InitiativeZhongquan Li @Guluisacat Hossein Lotfi @hosselot Trend Micro Zero Day InitiativeRodolphe BRUNETTI @eisw0lf Lupus NovaYann GASCUEL Alter SolutionsAdam M. Q1IQ @q1iqF NUS CuriOSityP1umer @p1umer Imperial Global Singaporelinjy HKUS3Labchluo WHUSecLabJohan Carlsson (joaxcar) PixiePoint Security Pwn2car & Rotiple(HyeongSeok Jang) Trend Micro Zero Day InitiativeAnonymous Trend Micro Zero Day InitiativeYiğit Can YILMAZ @yilmazcanyigit CertiK SkyFall Team Jonathan Bar Or @yo_yo_yo_jbo MicrosoftUri Katz (Oligo Security)
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Sequoia | <15.3 | 15.3 |
Apple macOS | <13.7.3 | 13.7.3 |
Apple macOS | <14.7.3 | 14.7.3 |
Apple macOS | ||
Apple macOS Sequoia | ||
Apple macOS | ||
<13.7.3 | ||
>=14.0<14.7.3 | ||
>=15.0<15.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-24100 has been classified as a high severity vulnerability due to its potential to allow unauthorized access to users' contacts.
To fix CVE-2025-24100, users should update to macOS Ventura 13.7.3, macOS Sequoia 15.3, or macOS Sonoma 14.7.3.
CVE-2025-24100 affects Apple macOS Ventura, macOS Sequoia, and macOS Sonoma versions prior to the specified updates.
CVE-2025-24100 is a logic issue related to improved restrictions on access to user contacts.
The specific reporting date for CVE-2025-24100 is not mentioned in the provided information.