First published: Tue Mar 18 2025(Updated: )
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS. Interaction with the libFontParser library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2024-54486.
Affected Software | Affected Version | How to fix |
---|---|---|
macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-25-166 is classified as medium, indicating a potential risk of sensitive information disclosure.
To fix ZDI-25-166, ensure that you update your Apple macOS to the latest version that includes the security patch.
ZDI-25-166 affects installations of Apple macOS that use the libFontParser library.
Yes, ZDI-25-166 can be exploited by remote attackers under certain conditions.
ZDI-25-166 may allow attackers to disclose sensitive information stored on affected Apple macOS installations.