Skip to content

Threat Research Knowledge Base

CVE-2024-44175

Description

CVE-2024-44175 is a vulnerability in Apple's macOS that could allow an application to access sensitive user data. The issue was addressed by Apple through improved validation of symlinks in macOS Sonoma 14.7.1 and macOS Sequoia 15. According to Kandji's analysis, this vulnerability involves a Time-of-Check to Time-of-Use (TOCTOU) race condition in the `diskarbitrationd` daemon. By exploiting this flaw, an attacker could escape the application sandbox and escalate privileges to root from a low-privileged user.

Get a Free Trial

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by an application. The severity of this issue has been assessed as follows:

NIST assessment

CVSS v3.1 Base Score: 5.5 (Medium)

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA-ADP assessment

CVSS v3.1 Base Score: 7.5 (High)

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Has been exploited in the wild

No

Operating systems impacted

  • macOS Sonoma (prior to 14.7.1)
  • macOS Sequoia (prior to 15)

Apps impacted

No apps impacted

Learn more about it

Kandji Blog: macOS Audit Story

Kandji Blog: macOS Audit Story

Part 1 of Kandji’s macOS Audit Story examines diskarbitrationd and storagekitd daemons, sandbox escapes, privilege escalations, and TCC bypasses, and how these issues were disclosed to Apple.

Read more

Related

Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by an application. The severity of this issue has been assessed as follows:

Grants unauthorized access to sensitive user information. The severity of this issue has been assessed as follows:

Exploitation of this vulnerability could lead to a denial-of-service condition by causing unexpected application termination. The severity of this issue has been assessed as follows:

Manage and secure your Apple devices at scale.

Laptop and 2 popup windows