CVE-2024-27825
Published May 13, 2024
·Updated
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to bypass certain Privacy preferences.
Credit
Kirin@@Pwnrin, Mickey Jin@@patch1t, Narendra Bhati(Suma Soft Pvt), Shaheen Fazim, Csaba Fitzl@@theevilbit(Kandji), LFY@@secsys, 小来来@@Smi1eSEC, yulige, Snoolie Keffaber@@0xilis, Robert Reichel, an anonymous researcher, CVE-2024-27806, Yann GASCUEL(Alter Solutions), CertiK SkyFall Team, ajajfxhj, Maksymilian Motyl(Immunity Systems), Junsung Lee(Trend Micro Zero Day Initiative), Manfred Paul@@_manfp(Trend Micro's Zero Day Initiative), Emilio Cobos(Mozilla), Lukas Bernhard(CISPA Helmholtz Center for Information Security), Nan Wang@@eternalsakura13(360 Vulnerability Research Institute), Joe Rutkowski@@Joe12387(Crawless), @@abrahamjuliot, Jeff Johnson(underpassapp), Minghao Lin(Baidu Security), (Baidu Security), Ye Zhang@@VAR10CK(Baidu Security), Meysam Firouzi@@R00tkitSMM, Amir Bazine(CrowdStrike Counter Adversary Operations), Karsten König(CrowdStrike Counter Adversary Operations), Pwn2car(Trend Micro's Zero Day Initiative), (Trend Micro's Zero Day Initiative), Michael DePlante@@izobashi(Trend Micro's Zero Day Initiative), Ron Masas(Imperva), pattern-f@@pattern_F_(Ant Security Light), an anonymous researcher(MIT CSAIL), (MIT CSAIL), Joseph Ravichandran@@0xjprx(MIT CSAIL), Pr(Bar), Pr(Hebrew University), EP, Nick Wellnhofer, Gil Pedersen, Dohyun Lee@@l33d0hyun, LFY@@secsys(Fudan University), Daniel Zajork, Joshua Zajork, Meysam Firouzi@@R00tkitsmm(Trend Micro Zero Day Initiative), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Scott Johnson(RIPEDA Consulting), Mykola Grymalyuk(RIPEDA Consulting), Jordy Witteman, Carlos Polop, Pedro Tôrres@@t0rr3sp3dr0
Affected Software
2 affected componentsFixes available
Apple macOS<14.5
14.5
macOS>=14.0<14.5
Event History
May 13, 2024
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
May 14, 2024
Data Sourced
via NVD·03:13 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27825?
CVE-2024-27825 has been classified as a moderate severity vulnerability affecting Intel-based Mac computers.
2
How do I fix CVE-2024-27825?
To fix CVE-2024-27825, update your macOS to version 14.5 or later.
3
Which systems are affected by CVE-2024-27825?
CVE-2024-27825 affects Intel-based Mac computers running macOS versions 14.0 to 14.4.
4
What is the nature of CVE-2024-27825?
CVE-2024-27825 is a downgrade issue that may allow apps to bypass certain Privacy preferences.
5
When was CVE-2024-27825 disclosed?
CVE-2024-27825 was disclosed in May 2024.