CVE-2025-24255

A file access issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to break out of its sandbox.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:19

Type Values Removed Values Added
Summary (en) A file access issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox. (en) A file access issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to break out of its sandbox.

03 Nov 2025, 22:18

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Apr/10 -
  • () http://seclists.org/fulldisclosure/2025/Apr/8 -
  • () http://seclists.org/fulldisclosure/2025/Apr/9 -

07 Apr 2025, 13:35

Type Values Removed Values Added
First Time Apple macos
Apple
References () https://support.apple.com/en-us/122373 - () https://support.apple.com/en-us/122373 - Vendor Advisory
References () https://support.apple.com/en-us/122374 - () https://support.apple.com/en-us/122374 - Vendor Advisory
References () https://support.apple.com/en-us/122375 - () https://support.apple.com/en-us/122375 - Vendor Advisory
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Summary
  • (es) Se solucionó un problema de acceso a archivos mejorando la validación de entrada. Este problema se solucionó en macOS Ventura 13.7.5, macOS Sequoia 15.4 y macOS Sonoma 14.7.5. Es posible que una aplicación pueda salir de su zona de pruebas.

01 Apr 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.4
CWE CWE-20

31 Mar 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 23:15

Updated : 2026-04-02 19:19


NVD link : CVE-2025-24255

Mitre link : CVE-2025-24255

CVE.ORG link : CVE-2025-24255


JSON object : View

Products Affected

apple

  • macos
CWE
CWE-20

Improper Input Validation