Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8968 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app with root privileges may be able to access private information. |
Tue, 28 Apr 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Symlink Handling Exploit Allowing Root Application to Access Private Information on macOS |
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 04 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple macos |
|
| CPEs | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apple
Apple macos |
Tue, 01 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 |
Tue, 01 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-59 | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 01 Apr 2025 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics |
cvssV3_1
|
Mon, 31 Mar 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app with root privileges may be able to access private information. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2026-04-02T18:26:14.441Z
Reserved: 2025-01-17T00:00:45.008Z
Link: CVE-2025-24242
Updated: 2025-11-03T21:10:21.055Z
Status : Modified
Published: 2025-03-31T23:15:21.433
Modified: 2025-11-03T22:18:35.247
Link: CVE-2025-24242
No data.
OpenCVE Enrichment
Updated: 2026-04-28T02:30:18Z
EUVD