First published: Tue Mar 18 2025(Updated: )
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS. Interaction with the ImageIO framework is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2024-54500.
Affected Software | Affected Version | How to fix |
---|---|---|
macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-CAN-25242 is categorized as a critical vulnerability due to its potential for remote exploitation.
To fix ZDI-CAN-25242, ensure that you install the latest security updates provided by Apple for macOS.
ZDI-CAN-25242 affects installations of Apple macOS that interact with the ImageIO framework.
ZDI-CAN-25242 allows remote attackers to disclose sensitive information from affected macOS systems.
Yes, interaction with the ImageIO framework is required to exploit the ZDI-CAN-25242 vulnerability.