← Browse

CVE-2025-24259

Medium

Elevated severity or exploit probability.

CVSS base
9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.8%
53.3th percentile
CISA KEV
Not listed
Weakness / dates
CWE-284
Published 2025-03-31 · modified 2026-07-23

Description

This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.

Affected

apple

References

Official: NVD · CVE.org