This issue was addressed with improved entitlements. This issue is fixed in macOS Sequoia 15. An app may be able to access removable volumes without user consent.
References
History

Fri, 14 Mar 2025 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 11 Mar 2025 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved entitlements. This issue is fixed in macOS Sequoia 15. An app may be able to access removable volumes without user consent.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2025-03-10T19:11:10.755Z

Updated: 2025-03-11T02:47:09.447Z

Reserved: 2024-12-03T22:50:35.492Z

Link: CVE-2024-54463

cve-icon Vulnrichment

Updated: 2025-03-11T02:46:49.328Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-10T19:15:38.290

Modified: 2025-03-14T12:00:22.240

Link: CVE-2024-54463

cve-icon Redhat

No data.