Description
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to bypass Privacy preferences.
Published: 2025-03-31
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privacy Bypass
Action: Patch
AI Analysis

Impact

A race condition in macOS allows an application to bypass the system’s privacy preferences, potentially enabling the app to access data that should be locked behind user consent. The flaw was mitigated by adding validation checks but the race remains in versions prior to macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5.

Affected Systems

Apple macOS deployments running versions older than Sequoia 15.4, Sonoma 14.7.5, or Ventura 13.7.5 are vulnerable, as they lack the fix that resolves the race condition.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity level, while the EPSS score of less than 1% suggests that widespread exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, further limiting known attacks. Based on the nature of a race condition, the likely attack vector is a local or privileged application that manipulates timing to gain premature access to privacy-protected data, although the description does not explicitly confirm this vector.

Generated by OpenCVE AI on April 28, 2026 at 11:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update macOS to the latest patch level (Sequoia 15.4, Sonoma 14.7.5, or Ventura 13.7.5).
  • Revoke or review application permissions for sensitive services to prevent excessive access.
  • If an update cannot be applied immediately, consider disabling or restricting applications that rely on the affected privacy preference interfaces.

Generated by OpenCVE AI on April 28, 2026 at 11:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8889 A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to bypass Privacy preferences.
History

Tue, 28 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Title Race Condition Allowing Application to Bypass macOS Privacy Preferences

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to bypass Privacy preferences. A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to bypass Privacy preferences.

Mon, 03 Nov 2025 22:30:00 +0000


Tue, 15 Apr 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Mon, 07 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to bypass Privacy preferences.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:07:41.826Z

Reserved: 2025-03-27T16:13:58.312Z

Link: CVE-2025-31188

cve-icon Vulnrichment

Updated: 2025-04-07T18:28:36.154Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:29.037

Modified: 2026-04-02T19:19:44.383

Link: CVE-2025-31188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T12:00:13Z

Weaknesses