Junglewise Threat Intelligence

CVE-2024-44219: Apple macOS Sequoia Improper Access Control in Permissions

CVE-2024-44219 · Severity: high · CVSS 7.5 · Published 2026-04-02

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A security vulnerability in macOS Sequoia could allow a malicious application with administrative (root) privileges to access a user's private information. This issue affects the privacy of personal data stored on the computer. Users should update to macOS Sequoia 15.1 to resolve this issue and prevent unauthorized data access by malicious software.

Technical details

A permissions issue (CWE-284) was identified in macOS Sequoia where additional restrictions were required to prevent unauthorized data access. A malicious application that has already obtained root privileges could exploit this flaw to bypass intended access controls and retrieve private information. The vulnerability was mitigated by implementing stricter permission checks and restrictions within the operating system. The fix is available in macOS Sequoia 15.1. While the CVSS vector provided by CISA-ADP suggests a network attack vector, the description specifically identifies a malicious application on the local system as the primary threat.

Affected products

  • Apple macOS Sequoia up to (excluding) 15.1

Timeline

  • 2024-10-24: patched: Fixed in macOS Sequoia 15.1 release
  • 2026-04-02: disclosed: Initial NVD publication

References

Related threats