CVE-2025-24170

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

11 Jun 2026, 19:16

Type Values Removed Values Added
References
  • () https://support.apple.com/en-us/122373 -
Summary (en) A logic issue was addressed with improved file handling. This issue is fixed in macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges. (en) A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

02 Apr 2026, 19:19

Type Values Removed Values Added
Summary (en) A logic issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sonoma 14.7.5. An app may be able to gain root privileges. (en) A logic issue was addressed with improved file handling. This issue is fixed in macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

03 Nov 2025, 21:19

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Apr/10 -
  • () http://seclists.org/fulldisclosure/2025/Apr/9 -

04 Apr 2025, 18:18

Type Values Removed Values Added
First Time Apple macos
Apple
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
References () https://support.apple.com/en-us/122374 - () https://support.apple.com/en-us/122374 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122375 - () https://support.apple.com/en-us/122375 - Release Notes, Vendor Advisory
Summary
  • (es) Se solucionó un problema lógico mejorando la gestión de archivos. Este problema se solucionó en macOS Ventura 13.7.5 y macOS Sonoma 14.7.5. Es posible que una aplicación obtenga privilegios de root.

01 Apr 2025, 05:15

Type Values Removed Values Added
CWE CWE-276
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

31 Mar 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 23:15

Updated : 2026-06-11 19:16


NVD link : CVE-2025-24170

Mitre link : CVE-2025-24170

CVE.ORG link : CVE-2025-24170


JSON object : View

Products Affected

apple

  • macos
CWE
CWE-276

Incorrect Default Permissions