ZDI-CAN-24156: ZDI-25-305: Apple XNU kernel vm_map Race Condition Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Apple macOS. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-31219.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24156?
The severity of ZDI-CAN-24156 has been rated at 8.8 on the CVSS scale.
How do I fix ZDI-CAN-24156?
To fix ZDI-CAN-24156, users should install the latest security updates provided by Apple for macOS.
Who is affected by the ZDI-CAN-24156 vulnerability?
Local attackers on affected installations of Apple macOS are at risk of exploiting the ZDI-CAN-24156 vulnerability.
What type of attack does ZDI-CAN-24156 enable?
ZDI-CAN-24156 enables local attackers to escalate privileges on the target system.
What must an attacker achieve to exploit ZDI-CAN-24156?
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit ZDI-CAN-24156.