Description
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.
Published: 2025-03-31
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Integrity compromise of protected file system areas
Action: Apply Patch
AI Analysis

Impact

The vulnerability stems from insufficient privilege checks that allow an application to modify files that should be protected by the operating system. This weakness means unprivileged software could alter system files or overwrite critical configuration data, directly impacting the integrity of the platform. The flaw is a classic improper access control issue, identified by CWE‑284, which can lead to unauthorized changes and potentially enable further privilege escalation.

Affected Systems

Apple macOS environments on versions before macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5 are affected. All prior releases lack the improved checks that were added in those updates.

Risk and Exploitability

The CVSS score of 6.8 indicates medium severity, and the EPSS score of less than 1% suggests a very low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would most likely need to run a malicious or compromised application locally on the target machine to exploit the weakness; network‑based exploitation is not supported by the information provided.

Generated by OpenCVE AI on April 28, 2026 at 02:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the operating system to macOS Sequoia 15.4 or later, macOS Sonoma 14.7.5, or macOS Ventura 13.7.5 to obtain the fixed checks.
  • If an upgrade is not immediately feasible, restrict the execution of untrusted applications that might attempt to write to protected filesystem locations, using Gatekeeper and the App Sandbox to enforce tighter permissions.
  • Monitor system logs and file integrity tools for unexpected changes to privileged directories as an additional detection measure.

Generated by OpenCVE AI on April 28, 2026 at 02:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8937 The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.
History

Tue, 28 Apr 2026 03:15:00 +0000

Type Values Removed Values Added
Title macOS Protected File System Modification Vulnerability

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system. The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

Mon, 03 Nov 2025 22:30:00 +0000


Mon, 07 Apr 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 01 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:20:24.963Z

Reserved: 2025-01-17T00:00:45.017Z

Link: CVE-2025-24272

cve-icon Vulnrichment

Updated: 2025-11-03T21:12:06.317Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:23.807

Modified: 2026-04-02T19:19:31.320

Link: CVE-2025-24272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T03:00:10Z

Weaknesses