CVE-2025-24173

This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

History

03 Nov 2025, 21:19

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Apr/10 -
  • () http://seclists.org/fulldisclosure/2025/Apr/11 -
  • () http://seclists.org/fulldisclosure/2025/Apr/12 -
  • () http://seclists.org/fulldisclosure/2025/Apr/4 -
  • () http://seclists.org/fulldisclosure/2025/Apr/5 -
  • () http://seclists.org/fulldisclosure/2025/Apr/8 -
  • () http://seclists.org/fulldisclosure/2025/Apr/9 -

03 Nov 2025, 20:17

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Apr/13 -

04 Apr 2025, 18:18

Type Values Removed Values Added
First Time Apple visionos
Apple macos
Apple iphone Os
Apple tvos
Apple
Apple ipados
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
References () https://support.apple.com/en-us/122371 - () https://support.apple.com/en-us/122371 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122372 - () https://support.apple.com/en-us/122372 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122373 - () https://support.apple.com/en-us/122373 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122374 - () https://support.apple.com/en-us/122374 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122375 - () https://support.apple.com/en-us/122375 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122377 - () https://support.apple.com/en-us/122377 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122378 - () https://support.apple.com/en-us/122378 - Release Notes, Vendor Advisory

02 Apr 2025, 16:17

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
Summary
  • (es) Este problema se solucionó con comprobaciones de derechos adicionales. Este problema está corregido en visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 y iPadOS 18.4, macOS Sequoia 15.4 y macOS Sonoma 14.7.5. Es posible que una aplicación pueda salir de su zona de pruebas.

31 Mar 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 23:15

Updated : 2025-11-03 21:19


NVD link : CVE-2025-24173

Mitre link : CVE-2025-24173

CVE.ORG link : CVE-2025-24173


JSON object : View

Products Affected

apple

  • iphone_os
  • visionos
  • tvos
  • ipados
  • macos
CWE
CWE-284

Improper Access Control