CVE-2025-24258

HIGH

macOS < 13.7.6, < 14.7.6, < 15.4 - Privilege Escalation to Root

Title source: llm
STIX 2.1

Description

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to gain root privileges.

References (5)

Core 5
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122373
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122717
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122718

Scores

CVSS v3 7.8
EPSS 0.0010
EPSS Percentile 26.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (4)
apple/macos < 13.7.6
Apple/macOS < 13.7.6
Apple/macOS < 14.7.6
Apple/macOS < 15.4
Published May 12, 2025
Tracked Since Feb 18, 2026