An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.2. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Accounts | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Appleevents | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Archiveutility | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Assets | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Automation | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Avevideoencoder | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Coreservices | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Diskarbitration | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Emoji | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Fileurl | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Findmy | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Imageio | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Iokit | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Iousbdevicefamily | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Kernel | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Libsystem | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Modelio | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Ncurses | — | — | Oct 14, 2024 | Feb 21, 2024 |
| Apple Osx Quarantine | — | Upgrade macOS to the latest version | Feb 19, 2024 | Feb 19, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub