CVE-2024-54520

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to overwrite arbitrary files.
References
Link Resource
https://support.apple.com/en-us/121839 Release Notes Vendor Advisory
https://support.apple.com/en-us/121840 Release Notes Vendor Advisory
https://support.apple.com/en-us/121842 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-27 22:15

Updated : 2025-03-24 18:15


NVD link : CVE-2024-54520

Mitre link : CVE-2024-54520

CVE.ORG link : CVE-2024-54520


JSON object : View

Products Affected

apple

  • macos
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-787

Out-of-bounds Write