Threat Research Knowledge Base Vulnerabilities CVE-2024-40855
CVE-2024-40855
Description
CVE-2024-40855 is a security vulnerability in Apple's DiskArbitration framework that could allow a sandboxed app to access sensitive user data. The issue was addressed by Apple through improved checks in macOS Sequoia 15, macOS Sonoma 14.7.1, and macOS Ventura 13.7.1.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by a sandboxed application. The severity of this issue has been assessed as follows:
NIST assessment
CVSS v3.1 Base Score: 5.5 (Medium)
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA-ADP assessment
CVSS v3.1 Base Score: 5.5 (Medium)
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Has been exploited in the wild
No
Operating systems impacted
- macOS Sequoia (prior to 15)
- macOS Sonoma (prior to 14.7.1)
- macOS Ventura (prior to 13.7.1)
Additional resources
Apps impacted
No apps impacted
Related
Exploitation of this vulnerability could lead to unauthorized access to sensitive location information by an application. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by an application. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by an application. The severity of this issue has been assessed as follows:
Manage and secure your Apple devices at scale.
