Skip to content

Threat Research Knowledge Base

CVE-2025-24236

Description

CVE-2025-24236 is a security vulnerability in Apple's macOS that could allow an application to access sensitive user data. The issue was addressed by Apple through additional sandbox restrictions in macOS Sequoia 15.4 and macOS Sonoma 14.7.5. The vulnerability was discovered by Csaba Fitzl (@theevilbit) and Nolan Astrein of Kandji.

Get a Free Trial

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by an application. The severity of this issue has been assessed as follows:

CISA-ADP assessment

CVSS v3.1 Base Score: 5.5 (Medium)

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Has been exploited in the wild

No

Operating systems impacted

  • macOS Sequoia (prior to 15.4)
  • macOS Sonoma (prior to 14.7.5)

Apps impacted

No apps impacted

Related

Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by an application. The severity of this issue has been assessed as follows:

Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by bypassing Privacy preferences. The severity of this issue has been assessed as follows:

Exploitation of this vulnerability could allow attackers to execute arbitrary code on the affected devices, leading to potential data breaches, unauthorized access, or further compromise of the system.The severity of this issue has been assessed as follows:

Manage and secure your Apple devices at scale.

Laptop and 2 popup windows