Description
The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to gain root privileges.
Published: 2025-05-12
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to root
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from missing permission checks that allow a malicious application to elevate its privileges to the system level. Classified as CWE‑280, it involves improper privilege management. A user who can install or run an untrusted app on the affected macOS can therefore gain root access, enabling full control over the system.

Affected Systems

Apple’s macOS operating system is affected, specifically versions before Sequoia 15.4, Sonoma 14.7.6, and Ventura 13.7.6. Systems running these earlier releases may be exploited by a local or user‑initiated attacker.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity; however, the EPSS score of less than 1% points to a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to install or execute a malicious app on the target device, a local attack scenario, and could result in complete system compromise if successful.

Generated by OpenCVE AI on April 28, 2026 at 01:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to a patched version such as Sequoia 15.4, Sonoma 14.7.6, or Ventura 13.7.6.
  • If an upgrade is not immediately possible, restrict installation of third‑party applications with elevated privileges and remove any unknown apps that request such rights.
  • Monitor system logs for suspicious privilege escalation activity and apply future security updates as soon as they become available.

Generated by OpenCVE AI on April 28, 2026 at 01:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14384 The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. A malicious app may be able to gain root privileges.
History

Tue, 28 Apr 2026 02:15:00 +0000

Type Values Removed Values Added
Title macOS Privilege Escalation via Improper Permission Checks

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. A malicious app may be able to gain root privileges. The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to gain root privileges.

Mon, 03 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
References

Tue, 27 May 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 13 May 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-280
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 12 May 2025 21:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. A malicious app may be able to gain root privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:08:46.144Z

Reserved: 2025-03-22T00:04:43.720Z

Link: CVE-2025-30453

cve-icon Vulnrichment

Updated: 2025-11-03T19:47:17.257Z

cve-icon NVD

Status : Modified

Published: 2025-05-12T22:15:21.280

Modified: 2026-04-02T19:19:39.707

Link: CVE-2025-30453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T02:00:15Z

Weaknesses