CVE-2024-27825: High severity Apple macOS vulnerability
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to bypass certain Privacy preferences.
Other sources
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleAVD. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
AppleMobileFileIntegrity. A downgrade issue was addressed with additional code-signing restrictions.
— Apple
RemoteViewServices. A logic issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-27826
- CVE-2024-27804
- CVE-2024-27837
- CVE-2024-27816
- CVE-2024-27825
- CVE-2024-27829
- CVE-2024-27841
- CVE-2024-23236
- CVE-2024-27805
- CVE-2024-27817
- CVE-2024-27831
- CVE-2024-27832
- CVE-2024-27827
- CVE-2024-27801
- CVE-2024-27836
- CVE-2024-27799
- CVE-2024-27818
- CVE-2024-27815
- CVE-2024-27823
- CVE-2024-27811
- CVE-2023-42893
- CVE-2024-23251
- CVE-2024-23282
- CVE-2024-27810
- CVE-2024-27800
- CVE-2024-27802
- CVE-2024-27857
- CVE-2024-27822
- CVE-2024-27824
- CVE-2024-27885
- CVE-2024-27813
- CVE-2024-27844
- CVE-2024-27843
- CVE-2024-27821
- CVE-2024-27855
- CVE-2024-27806
- CVE-2024-27798
- CVE-2024-27848
- CVE-2024-27847
- CVE-2024-27884
- CVE-2024-27842
- CVE-2024-27796
- CVE-2024-27834
- CVE-2024-27838
- CVE-2024-27808
- CVE-2024-27850
- CVE-2024-27851
- CVE-2024-27830
- CVE-2024-27820
- CVE-2024-40771
- CVE-2024-27856
Frequently Asked Questions
What is the severity of CVE-2024-27825?
CVE-2024-27825 has been classified as a moderate severity vulnerability affecting Intel-based Mac computers.
How do I fix CVE-2024-27825?
To fix CVE-2024-27825, update your macOS to version 14.5 or later.
Which systems are affected by CVE-2024-27825?
CVE-2024-27825 affects Intel-based Mac computers running macOS versions 14.0 to 14.4.
What is the nature of CVE-2024-27825?
CVE-2024-27825 is a downgrade issue that may allow apps to bypass certain Privacy preferences.
When was CVE-2024-27825 disclosed?
CVE-2024-27825 was disclosed in May 2024.