ZDI-25-305: Apple XNU kernel vm_map Race Condition Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Apple macOS. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-31219.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-305?
ZDI-25-305 has been assigned a CVSS rating of 8.8, indicating high severity.
How do I fix ZDI-25-305?
To fix ZDI-25-305, apply the security updates provided by Apple for affected macOS installations.
What does ZDI-25-305 affect?
ZDI-25-305 affects installations of Apple macOS that are vulnerable to local privilege escalation.
Who can exploit ZDI-25-305?
Local attackers who can execute low-privileged code on the target system can exploit ZDI-25-305.
Is ZDI-25-305 a remote or local vulnerability?
ZDI-25-305 is a local vulnerability requiring an attacker to have access to the system.