Description
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to bypass certain Privacy preferences.
Published: 2025-05-12
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privacy Bypass
Action: Update OS
AI Analysis

Impact

The vulnerability is a logic flaw, identified as CWE‑693, that was corrected with additional checks in a recent macOS update. The flaw permits an application to circumvent user-configured privacy preferences, potentially exposing or using sensitive data without explicit consent.

Affected Systems

Apple macOS versions older than macOS Sequoia 15.5, macOS Sonoma 14.7.6, and macOS Ventura 13.7.6 are susceptible to this flaw.

Risk and Exploitability

The CVSS score is 7.8, indicating a high risk to confidentiality because the app can read or access data beyond the user’s intent. The EPSS score of less than 1% shows that current exploitation activity is rare, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local or privileged application that requests elevated permissions, so the bug is most easily exploited when the attacker can run or install an application on the target machine.

Generated by OpenCVE AI on April 28, 2026 at 11:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the system to macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6 or newer.
  • If an upgrade is not immediately possible, apply all available macOS security updates, review and restrict privacy settings, and avoid granting unnecessary permissions to applications.
  • Refer to Apple’s support articles 122716, 122717, and 122718 for detailed guidance and any additional temporary mitigations.

Generated by OpenCVE AI on April 28, 2026 at 11:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14639 A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to bypass certain Privacy preferences.
History

Tue, 28 Apr 2026 11:45:00 +0000

Type Values Removed Values Added
Title macOS Privacy Preference Bypass Vulnerability

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to bypass certain Privacy preferences. A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to bypass certain Privacy preferences.

Mon, 03 Nov 2025 20:30:00 +0000


Tue, 27 May 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 13 May 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 12 May 2025 21:45:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to bypass certain Privacy preferences.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:15:07.368Z

Reserved: 2025-03-27T16:13:58.321Z

Link: CVE-2025-31224

cve-icon Vulnrichment

Updated: 2025-11-03T19:50:27.219Z

cve-icon NVD

Status : Modified

Published: 2025-05-12T22:15:23.147

Modified: 2026-04-02T19:19:50.720

Link: CVE-2025-31224

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T11:30:29Z

Weaknesses