vulnerability
OS X update for Login Window (CVE-2025-24136)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 3 | (AV:L/AC:M/Au:N/C:P/I:P/A:N) | Jan 27, 2025 | Jan 30, 2025 | Aug 13, 2025 |
Severity
3
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:N)
Published
Jan 27, 2025
Added
Jan 30, 2025
Modified
Aug 13, 2025
Description
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A malicious app may be able to create symlinks to protected regions of the disk.
Solutions
apple-osx-upgrade-13_7_3apple-osx-upgrade-14_7_3apple-osx-upgrade-15_3
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.