Description
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. "Block All Remote Content" may not apply for all mail previews.
Published: 2025-03-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted loading of remote content in mail previews
Action: Immediate Patch
AI Analysis

Impact

A permissions flaw in macOS prevents the sandbox from adequately restricting when remote content is rendered in email previews. Because the “Block All Remote Content” setting may not apply consistently, an attacker can cause arbitrary web resources to be fetched without user consent, potentially leaking sensitive information or delivering malicious payloads via the mail preview mechanism.

Affected Systems

Apple macOS users on versions prior to Sequoia 15.4, Sonoma 14.7.5, or Ventura 13.7.5 are affected. The vulnerability has been remedied in those releases.

Risk and Exploitability

The CVSS score of 9.8 signals a high‑severity flaw, yet the EPSS score is under 1%, indicating a low current exploitation probability. The issue is not yet listed in the CISA KEV catalog. Attackers would likely target mail clients through crafted messages that trigger preview rendering; given the severity and the unrestricted permission nature, the remote content exposure could aid further attacks such as phishing or data exfiltration.

Generated by OpenCVE AI on April 28, 2026 at 03:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest macOS update: Sequoia 15.4, Sonoma 14.7.5 or Ventura 13.7.5 to receive the sandbox restriction fix.
  • If updating immediately is not possible, disable or restrict mail preview functionality or enable the “Block All Remote Content” preference to prevent automatic rendering of external resources.
  • Verify that any third‑party mail clients or extensions are updated and enforce proper sandbox permissions to avoid granting elevated access to remote content.

Generated by OpenCVE AI on April 28, 2026 at 03:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9006 A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. "Block All Remote Content" may not apply for all mail previews.
History

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. "Block All Remote Content" may not apply for all mail previews. A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. "Block All Remote Content" may not apply for all mail previews.

Mon, 03 Nov 2025 21:30:00 +0000


Fri, 04 Apr 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Thu, 03 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Apr 2025 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. "Block All Remote Content" may not apply for all mail previews.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:07:45.632Z

Reserved: 2025-01-17T00:00:44.990Z

Link: CVE-2025-24172

cve-icon Vulnrichment

Updated: 2025-11-03T21:06:04.009Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:16.773

Modified: 2026-04-02T19:19:12.797

Link: CVE-2025-24172

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T03:30:19Z

Weaknesses