CRITICAL🇵🇱 Wersja polska

CVE-2024-54465

CVSS 9.8v3.1pub. 2024-12-12upd. 2025-11-03

A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileges.

🤖 AI Analysis
How it works

The problem results from improper state management (logic issue), partially classified as CWE-281 (improper behavior during privilege change). A malicious or compromised application can exploit this error to obtain higher system privileges than granted. Apple fixed the vulnerability by improving state management mechanisms in the system.

Impact

An attacker controlling an application running on the vulnerable system can obtain elevated privileges, potentially allowing complete system takeover, breach of confidentiality, integrity, and data availability.

Mitigation & patch

The system should be updated to macOS Sequoia 15.2 or newer. Patch is available through Apple's system update mechanism and at https://support.apple.com/en-us/121839

Who is affected

Apple macOS Sequoia in versions prior to 15.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apple macOS

    OS
    Apple
    < 15.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-31200CRITICAL9.8⚠ KEVPL ✓same product

Apple — memory corruption (RCE) w przetwarzaniu strumieni audio

CVE-2025-31201CRITICAL9.8⚠ KEVPL ✓same product

Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach