CVE-2025-24138

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A malicious application may be able to leak sensitive user information.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:19

Type Values Removed Values Added
Summary (en) This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A malicious application may be able to leak sensitive user information. (en) This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A malicious application may be able to leak sensitive user information.

03 Nov 2025, 21:19

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Jan/15 -
  • () http://seclists.org/fulldisclosure/2025/Jan/16 -
  • () http://seclists.org/fulldisclosure/2025/Jan/17 -

24 Mar 2025, 17:15

Type Values Removed Values Added
CWE CWE-200

03 Mar 2025, 22:45

Type Values Removed Values Added
References () https://support.apple.com/en-us/122068 - () https://support.apple.com/en-us/122068 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122069 - () https://support.apple.com/en-us/122069 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122070 - () https://support.apple.com/en-us/122070 - Release Notes, Vendor Advisory
CWE NVD-CWE-noinfo
First Time Apple
Apple macos
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

18 Feb 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : unknown
CWE CWE-922

28 Jan 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-922
Summary
  • (es) Este problema se solucionó mediante con una mejor gestión del estado. Este problema se solucionó en macOS Ventura 13.7.3, macOS Sequoia 15.3 y macOS Sonoma 14.7.3. Una aplicación malintencionada podría filtrar información confidencial del usuario.

27 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 22:15

Updated : 2026-04-02 19:19


NVD link : CVE-2025-24138

Mitre link : CVE-2025-24138

CVE.ORG link : CVE-2025-24138


JSON object : View

Products Affected

apple

  • macos
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor