Description
An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to gain root privileges.
Published: 2025-05-12
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to root
Action: Patch Now
AI Analysis

Impact

The vulnerability is an input validation flaw in macOS where untrusted input handling was removed, allowing a malicious application to obtain root privileges. The weakness is classified as CWE‑20 and is explicitly stated to be fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, and macOS Ventura 13.7.6.

Affected Systems

Apple’s macOS operating system is affected, specifically earlier releases of Sequoia, Sonoma, and Ventura. The issue has been resolved in macOS Sequoia 15.5, macOS Sonoma 14.7.6, and macOS Ventura 13.7.6; any earlier versions that have not received these updates remain vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score of less than 1% shows that exploitation is currently unlikely, and the vulnerability is not listed in CISA KEV. Based on the description, a local malicious application that supplies crafted input could trigger the flaw and elevate privileges, making the risk significant despite the low exploitation probability.

Generated by OpenCVE AI on April 28, 2026 at 11:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to macOS Sequoia 15.5, macOS Sonoma 14.7.6, or macOS Ventura 13.7.6 where the vulnerable code has been removed.
  • If an immediate upgrade is not possible, enforce strict application control by enabling Gatekeeper and limiting execution of untrusted applications to reduce exposure to local malicious code.
  • Continuously monitor the system for signs of privilege escalation, such as unexpected root-owned processes, and audit logs to detect anomalous behavior.

Generated by OpenCVE AI on April 28, 2026 at 11:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14632 An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A malicious app may be able to gain root privileges.
History

Tue, 28 Apr 2026 11:45:00 +0000

Type Values Removed Values Added
Title macOS Input Validation Vulnerability Enabling Root Privilege Escalation

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A malicious app may be able to gain root privileges. An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to gain root privileges.

Mon, 03 Nov 2025 20:30:00 +0000


Tue, 27 May 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 13 May 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 13 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 12 May 2025 21:45:00 +0000

Type Values Removed Values Added
Description An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A malicious app may be able to gain root privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:26:38.707Z

Reserved: 2025-01-17T00:00:45.017Z

Link: CVE-2025-24274

cve-icon Vulnrichment

Updated: 2025-05-13T20:01:17.977Z

cve-icon NVD

Status : Modified

Published: 2025-05-12T22:15:20.440

Modified: 2026-04-02T19:19:31.680

Link: CVE-2025-24274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T11:30:29Z

Weaknesses