Junglewise Threat Intelligence

CVE-2025-24165: Apple macOS unexpected system termination via permissions issue

CVE-2025-24165 · Severity: info · CVSS 5.5 · Published 2026-06-11

Technologies: Apple macOS Sonoma, Apple macOS Ventura. Vendors: Apple.

Executive brief

A security vulnerability in macOS could allow a malicious application to cause the entire computer to crash or restart unexpectedly. This issue affects several versions of the macOS operating system used on Apple laptops and desktops. Exploiting this flaw could lead to data loss for unsaved work or temporary service interruptions. Apple has released software updates to resolve this issue by implementing stricter permission controls.

Technical details

A permissions vulnerability exists in macOS Sequoia, Sonoma, and Ventura that can be triggered by a local application. The flaw stems from insufficient restrictions within the operating system's permission handling logic. An attacker can exploit this by running a malicious app on the target system, leading to a kernel panic or unexpected system termination (DoS). Apple addressed the issue by implementing additional restrictions to the affected component. Patches are available in macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5.

Affected products

  • Apple macOS Sequoia Before 15.4
  • Apple macOS Sonoma Before 14.7.5
  • Apple macOS Ventura Before 13.7.5

Timeline

  • 2025-03-31: patched: Initial release of security updates for macOS 15.4, 14.7.5, and 13.7.5.
  • 2026-06-11: disclosed: CVE-2025-24165 published to the NVD.

References

Related threats