Passwordless access that adapts to every context
Manage every device with one lightweight agent
Stay audit-ready with continuous evidence collection
Automating compliance, insights, and actions from a single interface.
CVE-2024-44175 is a vulnerability in Apple's macOS that could allow an application to access sensitive user data. The issue was addressed by Apple through improved validation of symlinks in macOS Sonoma 14.7.1 and macOS Sequoia 15. According to Kandji's analysis, this vulnerability involves a Time-of-Check to Time-of-Use (TOCTOU) race condition in the `diskarbitrationd` daemon. By exploiting this flaw, an attacker could escape the application sandbox and escalate privileges to root from a low-privileged user.
Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by an application. The severity of this issue has been assessed as follows:
CVE-2024-44196 is a permissions issue within Apple's PackageKit framework that could allow an application to modify protected parts of the file system.
Learn MoreCVE-2024-54477 allows an application to access sensitive user data. Apple mitigated the vulnerability through stricter checks in recent updates. Reported by Mickey Jin (@patch1t) and Csaba Fitzl (@theevilbit) of Kandji.
Learn MoreCVE-2025-24162 is a vulnerability in Apple's WebKit engine that could lead to an unexpected process crash when processing maliciously crafted web content. The issue was addressed by Apple through improved state management in the affected systems.
Learn MoreIru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.