Description
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.
Published: 2025-03-31
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Update macOS
AI Analysis

Impact

A vulnerability in macOS allowed a malicious application to read private data. The flaw was mitigated by removing the vulnerable code, but prior to that, an attacker could leverage an exposed interface to access sensitive information, resulting in disclosure of confidential data. This weakness aligns with CWE‑200, where information is revealed to an unauthorized party.

Affected Systems

The flaw affected Apple macOS versions prior to Sequoia 15.4, Sonoma 14.7.5, and Ventura 13.7.5. All releases newer than these contain the fix.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate risk. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a malicious local application that the user installs; based on the description, it is inferred that the attacker could exploit an exposed interface to read protected data.

Generated by OpenCVE AI on April 28, 2026 at 19:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update macOS to a version where the vulnerability is fixed (Sequoia 15.4 or later, Sonoma 14.7.5 or later, Ventura 13.7.5 or later).
  • Ensure Gatekeeper is enabled to prevent installation of unsigned applications.
  • Configure MDM or macOS supervision to require notarization for all applications, blocking execution of unverified local code.

Generated by OpenCVE AI on April 28, 2026 at 19:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8929 This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.
History

Tue, 28 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Title macOS Private Information Disclosure via Vulnerable Code

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information. This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.

Mon, 03 Nov 2025 22:30:00 +0000


Mon, 07 Apr 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Wed, 02 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:11:51.289Z

Reserved: 2025-01-17T00:00:45.019Z

Link: CVE-2025-24276

cve-icon Vulnrichment

Updated: 2025-11-03T21:12:14.716Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:24.003

Modified: 2026-04-02T19:19:31.853

Link: CVE-2025-24276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T19:15:25Z

Weaknesses