First published: Mon Jan 27 2025(Updated: )
A path handling issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to read files outside of its sandbox.
Credit: product-security@apple.com Wang Yu CyberservalKirin @Pwnrin Google Threat Analysis Group Desmond Trend Micro Zero Day InitiativePwn2car & Rotiple(HyeongSeok Jang) Trend Micro Zero Day InitiativeArsenii Kostromin (0x3c3e) Joshua Jones DongJun Kim @smlijun JongSeong Kim in Enki WhiteHat @nevul37 D4m0n Joseph Ravichandran @0xjprx MIT CSAILpattern-f @pattern_F_ an anonymous researcher 云散 Mickey Jin @patch1t Pedro Tôrres @t0rr3sp3dr0 神罚 @Pwnrin Anonymous Trend Micro Zero Day InitiativeYiğit Can YILMAZ @yilmazcanyigit Michael DePlante @izobashi Trend Micro Zero Day InitiativeZhongquan Li @Guluisacat Hossein Lotfi @hosselot Trend Micro Zero Day InitiativeRodolphe BRUNETTI @eisw0lf Lupus NovaJonathan Bar Or @yo_yo_yo_jbo MicrosoftYann GASCUEL Alter SolutionsAdam M. PixiePoint Security Minghao Lin @Y1nKoc Zhejiang Universitybabywu Zhejiang University Zhejiang UniversityXingwei Lin Zhejiang UniversityPwn2car & Rotiple (HyeongSeok Jang) Trend Micro Zero Day InitiativeCVE-2025-24085 Matej Moravec @MacejkoMoravec Michael (Biscuit) Thomas @social.lol) @biscuit Josh Parnham @joshparnham @RenwaX23 Q1IQ @q1iqF NUS CuriOSityP1umer @p1umer Imperial Global Singaporelinjy HKUS3Labchluo WHUSecLabJohan Carlsson (joaxcar) CertiK SkyFall Team Bohdan Stasiuk @Bohdan_Stasiuk Uri Katz (Oligo Security)
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <14.7.3 | 14.7.3 |
macOS | <15.3 | 15.3 |
macOS Ventura | <13.7.3 | 13.7.3 |
macOS Ventura | ||
macOS | ||
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-24115 is classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
To fix CVE-2025-24115, update to the latest versions: macOS Ventura 13.7.3, macOS Sequoia 15.3, or macOS Sonoma 14.7.3.
The potential impacts of CVE-2025-24115 include unauthorized access to files outside of an application’s sandbox.
CVE-2025-24115 affects macOS Ventura prior to 13.7.3, macOS Sequoia prior to 15.3, and macOS Sonoma prior to 14.7.3.
Yes, CVE-2025-24115 includes a path handling issue that can affect AirPlay functionality in the vulnerable macOS versions.