Description
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.
Published: 2025-03-31
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of protected file system
Action: Apply Patch
AI Analysis

Impact

A flaw in macOS permits an application to write to protected portions of the file system. This vulnerability was fixed by removing the vulnerable code from the operating system. Exploiting this weakness can allow an attacker to replace or tamper with critical system files, potentially compromising the integrity of core OS components.

Affected Systems

Apple macOS versions released before Sequoia 15.4, Sonoma 14.7.5, and Ventura 13.7.5 are affected. Apple has addressed the issue in those patched releases by eliminating the vulnerable code. Systems remaining on earlier releases could permit local applications to modify protected files.

Risk and Exploitability

The CVSS score of 5.5 indicates medium severity, while an EPSS score of less than 1% reflects a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that exploitation requires local execution of a malicious application or elevated privileges; a remote attack vector is not explicitly described. The availability of a local exploit coupled with the potential to alter core OS files poses a moderate risk to affected systems.

Generated by OpenCVE AI on April 28, 2026 at 22:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to Apple macOS Sequoia 15.4, Sonoma 14.7.5, or Ventura 13.7.5, where the vulnerable code has been removed.
  • Restrict the execution of local, unsigned applications by enforcing Gatekeeper or signed‑only policies, and limit software that can run with elevated privileges.
  • Enable macOS Integrity Protection, review file permissions to ensure protected directories remain write‑protected, and monitor for unauthorized changes.

Generated by OpenCVE AI on April 28, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8893 This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.
History

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system. This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

Mon, 03 Nov 2025 22:30:00 +0000


Fri, 04 Apr 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 01 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:25:37.915Z

Reserved: 2025-03-27T16:13:58.311Z

Link: CVE-2025-31187

cve-icon Vulnrichment

Updated: 2025-04-01T15:38:20.877Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:28.943

Modified: 2026-04-02T19:19:44.190

Link: CVE-2025-31187

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T23:00:13Z

Weaknesses