Skip to content

Threat Research Knowledge Base

CVE-2024-54469

Description

CVE-2024-54469 is a security vulnerability in Apple's FileProvider component that could allow a local user to leak sensitive user information. The issue was addressed by Apple through improved checks in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15, iOS 18, iPadOS 18, and visionOS 2.

Get a Free Trial

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive user information by a local user. The severity of this issue has been assessed as follows:

NIST assessment

CVSS v3.1 Base Score: 5.5 (Medium)

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA-ADP assessment

CVSS v3.1 Base Score: 5.5 (Medium)

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Has been exploited in the wild

No

Operating systems impacted

  • macOS Ventura (prior to 13.7)
  • macOS Sonoma (prior to 14.7)
  • macOS Sequoia (prior to 15)
  • iOS (prior to 18)
  • iPadOS (prior to 18)
  • visionOS (prior to 2)

Apps impacted

No apps impacted

Related

Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by an application. The severity of this issue has been assessed as follows:

Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by an application. The severity of this issue has been assessed as follows:

Grants unauthorized access to sensitive user information. The severity of this issue has been assessed as follows:

Manage and secure your Apple devices at scale.

Laptop and 2 popup windows