Description
CVE-2025-24236 is a security vulnerability in Apple's macOS that could allow an application to access sensitive user data. The issue was addressed by Apple through additional sandbox restrictions in macOS Sequoia 15.4 and macOS Sonoma 14.7.5. The vulnerability was discovered by Csaba Fitzl (@theevilbit) and Nolan Astrein of Kandji.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by an application. The severity of this issue has been assessed as follows:
CVE-2023-23533
CVE-2023-23533 is a logic issue within macOS that could allow an application to modify protected parts of the file system. According to Kandji's analysis, this vulnerability allowed an attacker to swap the installer package after the system verified its code signature. The system would then install
Learn MoreCVE-2024-40783
CVE-2024-40783 is a security vulnerability in Apple's macOS that could allow a malicious application to bypass Privacy preferences. The issue was addressed by Apple through improved restriction of data container access in macOS Sonoma 14.6, macOS Ventura 13.6.8, and macOS Monterey 12.7.6.
Learn MoreCVE-2024-4558
CVE-2024-4558 is a use-after-free vulnerability in the ANGLE component of Google Chrome. Processing maliciously crafted web content may lead to an unexpected process crash.
Learn More