Description
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to enable iCloud storage features without user consent.
Published: 2025-03-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized iCloud storage enablement without user consent
Action: Patch Immediately
AI Analysis

Impact

A permission flaw in macOS allows an application to enable iCloud storage features without the user’s consent, effectively bypassing the intended access control. The weakness is a Wrong Access Control (CWE‑276). This could let a malicious or compromised app store data in the user’s iCloud account without authorization, exposing personal information and undermining privacy.

Affected Systems

Apple macOS products are affected. The vulnerability is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5. Any earlier releases remain vulnerable.

Risk and Exploitability

The CVSS score of 9.8 signals a critical level of risk and a high potential impact. The EPSS score of less than 1% indicates a very low current likelihood of exploitation, and the issue is not yet listed in the CISA KEV catalog. The likely attack vector is local: an application that runs on the affected macOS system can trigger the iCloud storage feature without prompting the user. No evidence is provided that remote exploitation is possible, but the flaw runs with the permissions of the executing application, making it a serious concern for any app that is installed or downloaded.

Generated by OpenCVE AI on April 28, 2026 at 02:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to Sequoia 15.4, Sonoma 14.7.5, or Ventura 13.7.5 or newer to apply the fix.
  • Restart the system after installing the update to ensure the new permissions checks take effect.
  • Adjust iCloud storage settings to limit or review apps that are allowed to use iCloud, reducing the risk of unintended data uploads.

Generated by OpenCVE AI on April 28, 2026 at 02:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8996 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to enable iCloud storage features without user consent.
History

Tue, 28 Apr 2026 03:15:00 +0000

Type Values Removed Values Added
Title iCloud Storage Enablement Without Consent via macOS Permissions Flaw

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to enable iCloud storage features without user consent. A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to enable iCloud storage features without user consent.

Mon, 03 Nov 2025 21:30:00 +0000


Mon, 07 Apr 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 01 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to enable iCloud storage features without user consent.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:16:40.643Z

Reserved: 2025-01-17T00:00:45.001Z

Link: CVE-2025-24207

cve-icon Vulnrichment

Updated: 2025-04-01T20:50:13.646Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:18.680

Modified: 2026-04-02T19:19:18.953

Link: CVE-2025-24207

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T03:00:10Z

Weaknesses