Description
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access arbitrary files.
Published: 2025-03-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from improper state management in macOS, enabling a malicious application to read arbitrary files on the device. This can lead to disclosure of sensitive data stored on user or system volumes, potentially providing a foothold for further attacks. The flaw is an instance of information‑disclosure weakness under CWE‑200.

Affected Systems

The fix is included in macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5. Any macOS installation older than those versions—including Sequoia 15.3, Sonoma 14.6, Ventura 13.6 and earlier—is vulnerable. The issue has been declared for all Apple macOS products.

Risk and Exploitability

The CVSS score of 9.8 signals a severe risk, while the EPSS score of less than 1% indicates a low likelihood of exploitation as of now. The vulnerability is not present in the CISA KEV catalog. The primary attack vector is likely a local malicious application that takes advantage of the state‑management flaw to read protected files. No remote exploitation or network access is implied directly in the description.

Generated by OpenCVE AI on April 28, 2026 at 11:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the OS update, upgrading to Sequoia 15.4, Sonoma 14.7.5, or Ventura 13.7.5.
  • Restrict installation of applications to those signed by trusted developers and enable Gatekeeper to block unsigned software.
  • Monitor system logs for unauthorized file access incidents and, if necessary, apply additional local file‑access controls.

Generated by OpenCVE AI on April 28, 2026 at 11:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8970 This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access arbitrary files.
History

Tue, 28 Apr 2026 12:00:00 +0000

Type Values Removed Values Added
Title Arbitrary File Access by Malicious Apps via State Management Bug in macOS

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access arbitrary files. This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access arbitrary files.

Mon, 03 Nov 2025 21:30:00 +0000


Mon, 07 Apr 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 01 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access arbitrary files.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:19:57.982Z

Reserved: 2025-01-17T00:00:45.006Z

Link: CVE-2025-24232

cve-icon Vulnrichment

Updated: 2025-04-01T13:21:30.565Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:20.480

Modified: 2026-04-02T19:19:23.337

Link: CVE-2025-24232

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T11:45:30Z

Weaknesses