Description
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access user-sensitive data.
Published: 2025-03-31
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to user-sensitive data
Action: Monitor
AI Analysis

Impact

A race condition in macOS (CWE-362) allows an application to read user‑sensitive data that should not be available to it. The vulnerability was remedied by adding additional validation checks. Based on the description, it is inferred that before the fix, an app that could coordinate timed operations might trigger the race to obtain protected information.

Affected Systems

Apple macOS builds older than macOS Sequoia 15.4, macOS Sonoma 14.7.5, or macOS Ventura 13.7.5 are impacted. Systems running those or earlier releases are susceptible.

Risk and Exploitability

The CVSS score of 4.7 indicates a moderate severity and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local or application‑level exploitation where a malicious app coordinates timed operations to trigger the race condition, thereby reading data that normally requires higher privileges.

Generated by OpenCVE AI on April 28, 2026 at 19:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to the latest patch version—macOS Sequoia 15.4, macOS Sonoma 14.7.5, or macOS Ventura 13.7.5.
  • Reboot the Mac after the upgrade to ensure that kernel components are restarted under the new validated code.
  • Remove or restrict the use of applications that handle sensitive data until the OS is updated, thereby limiting the attack surface while the patch is applied.

Generated by OpenCVE AI on April 28, 2026 at 19:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8961 A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.
History

Tue, 28 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Title Race Condition Allows Unauthorized Access to User‑Sensitive Data

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data. A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access user-sensitive data.

Mon, 03 Nov 2025 22:30:00 +0000


Fri, 04 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 01 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:09:46.066Z

Reserved: 2025-01-17T00:00:45.008Z

Link: CVE-2025-24240

cve-icon Vulnrichment

Updated: 2025-11-03T21:10:14.720Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:21.247

Modified: 2026-04-02T19:19:24.950

Link: CVE-2025-24240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T19:15:25Z

Weaknesses