Description
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.
Published: 2025-03-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation (inferred)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability could allow an application to modify protected parts of the file system. The description does not detail the exact exploitation mechanism, but the associated CWE‑787 suggests a buffer overflow or out‑of‑bounds write. This could compromise system integrity and confidentiality, and may enable privilege escalation if the flaw is triggered in a privileged context.

Affected Systems

Apple macOS is affected; the fix is delivered in macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5. No other versions are confirmed to be vulnerable, but any macOS system not updated to at least one of these releases may still be at risk.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity. EPSS indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local: an attacker able to run a malicious or compromised application could potentially trigger the flaw and modify protected filesystem components. If a user runs such software, the exploit could result in system compromise.

Generated by OpenCVE AI on April 28, 2026 at 19:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the macOS update to at least Sequoia 15.4, Sonoma 14.7.5, or Ventura 13.7.5 on every affected machine.
  • If immediate update is not possible, restrict the application using Gatekeeper and the system’s sandbox features to limit its ability to touch protected directories, and consider disabling any unnecessary privileged services via System Preferences > Security & Privacy.
  • Monitor system logs for unauthorized file modifications and configure alerts for changes to critical system directories.

Generated by OpenCVE AI on April 28, 2026 at 19:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8983 The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.
History

Tue, 28 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Title Vulnerability Allowing Modification of Protected File System on macOS

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system. The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

Mon, 03 Nov 2025 21:30:00 +0000


Mon, 07 Apr 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 01 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:15:54.112Z

Reserved: 2025-01-17T00:00:45.006Z

Link: CVE-2025-24231

cve-icon Vulnrichment

Updated: 2025-04-01T14:02:50.872Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:20.387

Modified: 2026-04-02T19:19:23.157

Link: CVE-2025-24231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T19:15:25Z

Weaknesses