First published: Mon Jan 27 2025(Updated: )
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to modify protected parts of the file system.
Credit: product-security@apple.com Kirin @Pwnrin Bohdan Stasiuk @Bohdan_Stasiuk Mickey Jin @patch1t Minghao Lin @Y1nKoc Zhejiang Universitybabywu Zhejiang University Zhejiang UniversityXingwei Lin Zhejiang UniversityWang Yu CyberservalGoogle Threat Analysis Group Desmond Trend Micro Zero Day InitiativePwn2car & Rotiple (HyeongSeok Jang) Trend Micro Zero Day InitiativeCVE-2025-24085 Matej Moravec @MacejkoMoravec Arsenii Kostromin (0x3c3e) Joshua Jones DongJun Kim @smlijun JongSeong Kim in Enki WhiteHat @nevul37 D4m0n Joseph Ravichandran @0xjprx MIT CSAILan anonymous researcher pattern-f @pattern_F_ Michael (Biscuit) Thomas @social.lol) @biscuit 云散 Pedro Tôrres @t0rr3sp3dr0 Josh Parnham @joshparnham 神罚 @Pwnrin @RenwaX23 Michael DePlante @izobashi Trend Micro Zero Day InitiativeZhongquan Li @Guluisacat Hossein Lotfi @hosselot Trend Micro Zero Day InitiativeRodolphe BRUNETTI @eisw0lf Lupus NovaYann GASCUEL Alter SolutionsAdam M. Q1IQ @q1iqF NUS CuriOSityP1umer @p1umer Imperial Global Singaporelinjy HKUS3Labchluo WHUSecLabJohan Carlsson (joaxcar) PixiePoint Security Pwn2car & Rotiple(HyeongSeok Jang) Trend Micro Zero Day InitiativeAnonymous Trend Micro Zero Day InitiativeYiğit Can YILMAZ @yilmazcanyigit CertiK SkyFall Team Jonathan Bar Or @yo_yo_yo_jbo MicrosoftUri Katz (Oligo Security)
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <14.7.3 | 14.7.3 |
Apple iOS and macOS | <13.7.3 | |
Apple iOS and macOS | >=14.0<14.7.3 | |
Apple iOS and macOS | >=15.0<15.3 | |
macOS | <15.3 | 15.3 |
macOS Ventura | <13.7.3 | 13.7.3 |
macOS Ventura | ||
macOS | ||
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-24114 is classified as a moderate severity vulnerability due to the potential impact on file system protections.
To resolve CVE-2025-24114, update to macOS Ventura 13.7.3, macOS Sequoia 15.3, or macOS Sonoma 14.7.3.
CVE-2025-24114 describes a permissions issue that could allow an app to modify protected areas of the file system.
CVE-2025-24114 affects macOS Ventura, macOS Sequoia, and macOS Sonoma prior to their respective fixed versions.
CVE-2025-24114 was addressed with additional restrictions and improved input validation to prevent exploitation.