This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1. An app may be able to access sensitive user data.
                
            References
                    | Link | Resource | 
|---|---|
| https://support.apple.com/en-us/121238 | Release Notes Vendor Advisory | 
| https://support.apple.com/en-us/121570 | Release Notes Vendor Advisory | 
Configurations
                    History
                    30 Oct 2024, 17:14
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 5.5 | 
| CWE | CWE-59 | |
| First Time | Apple macos Apple | |
| References | () https://support.apple.com/en-us/121238 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/121570 - Release Notes, Vendor Advisory | |
| CPE | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | 
30 Oct 2024, 16:35
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-922 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.5 | 
29 Oct 2024, 14:34
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
28 Oct 2024, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-10-28 21:15
Updated : 2024-10-30 17:14
NVD link : CVE-2024-44175
Mitre link : CVE-2024-44175
CVE.ORG link : CVE-2024-44175
JSON object : View
Products Affected
                apple
- macos
