CVE-2024-44264

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious app may be able to create symlinks to protected regions of the disk.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:18

Type Values Removed Values Added
References
  • () https://support.apple.com/en-us/121564 -
Summary (en) This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. A malicious app may be able to create symlinks to protected regions of the disk. (en) This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious app may be able to create symlinks to protected regions of the disk.

03 Nov 2025, 23:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Oct/11 -
  • () http://seclists.org/fulldisclosure/2024/Oct/12 -
  • () http://seclists.org/fulldisclosure/2024/Oct/13 -

30 Oct 2024, 18:37

Type Values Removed Values Added
References () https://support.apple.com/en-us/121568 - () https://support.apple.com/en-us/121568 - Vendor Advisory
References () https://support.apple.com/en-us/121570 - () https://support.apple.com/en-us/121570 - Vendor Advisory
First Time Apple
Apple macos
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-59

29 Oct 2024, 14:34

Type Values Removed Values Added
Summary
  • (es) Este problema se solucionó con una validación mejorada de los enlaces simbólicos. Este problema se solucionó en macOS Ventura 13.7.1 y macOS Sonoma 14.7.1. Una aplicación malintencionada podría crear enlaces simbólicos a regiones protegidas del disco.

28 Oct 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-28 21:15

Updated : 2026-04-02 19:18


NVD link : CVE-2024-44264

Mitre link : CVE-2024-44264

CVE.ORG link : CVE-2024-44264


JSON object : View

Products Affected

apple

  • macos
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')