Description
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.
Published: 2025-03-31
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to protected user data
Action: Apply Patch
AI Analysis

Impact

A permissions flaw allowed any application to bypass standard access controls and read user data that should have remained private. The weakness, classified as a permissions error, lets a malicious or compromised app read protected files or information, disrupting user confidentiality but not integrity or availability directly. The vulnerability existed before Apple addressed it by removing vulnerable code and installing additional checks, meaning the impact remains if the affected code is still present in the system.

Affected Systems

Apple macOS users affected by this flaw include all releases prior to macOS Sequoia 15.4, macOS Sonoma 14.7.5 and macOS Ventura 13.7.5. The issue was patched in those specific versions, so systems running earlier releases have the vulnerability exposed.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity, but the EPSS score of less than 1 % implies that real‑world exploitation is unlikely at present. The flaw is not listed in the CISA KEV catalog, further suggesting limited known exploitation. Attackers would need to execute or run a third‑party application on the target machine; the vulnerability is therefore exploitable via local privilege escalation or by tricking users into installing malicious software. Because the attack does not require network access, organizations that enforce strict application whitelisting or use macOS security features can reduce risk.

Generated by OpenCVE AI on April 28, 2026 at 02:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the operating system to macOS Sequoia 15.4, macOS Sonoma 14.7.5 or macOS Ventura 13.7.5 or newer
  • If an immediate upgrade is not possible, enforce strict application signing policies and disable or restrict the execution of unsigned or untrusted applications
  • Maintain up‑to‑date malware protection and enable System Integrity Protection to reduce the likelihood that unauthorized apps can execute the vulnerable code

Generated by OpenCVE AI on April 28, 2026 at 02:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8895 A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.
History

Tue, 28 Apr 2026 03:00:00 +0000

Type Values Removed Values Added
Title Application may access protected user data due to permissions flaw

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data. A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.

Mon, 03 Nov 2025 22:30:00 +0000


Fri, 04 Apr 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 01 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:20:51.910Z

Reserved: 2025-03-22T00:04:43.721Z

Link: CVE-2025-30460

cve-icon Vulnrichment

Updated: 2025-04-01T18:19:10.404Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:27.397

Modified: 2026-04-02T19:19:40.793

Link: CVE-2025-30460

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T02:45:11Z

Weaknesses