CVE-2025-24278

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 31, 2025
Updated: Apr 4, 2025
CWE ID 59

Summary

CVE-2025-24278 is a vulnerability affecting macOS that has been addressed through improved validation of symlinks. This issue could allow an application to access protected user data. The vulnerability has been resolved in the latest versions of macOS Ventura 13.7.5, macOS Sequoia 15.4, and macOS Sonoma 14.7.5. By enhancing the handling of symlinks, the risk of unauthorized access to sensitive information has been mitigated.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share