Apple PackageKit Logic Issue Allowing Modification of Protected File System Areas

Vulnerability

A logic vulnerability in the PackageKit component of macOS Ventura, macOS Sequoia, and macOS Sonoma allows applications to modify protected areas of the file system. This issue has been addressed with improved validation checks. The vulnerability was reported by Mickey Jin (@patch1t) and is also present in the DiskArbitration component, where similar permissions issues were fixed.

Impact

Exploitation of this vulnerability could lead to unauthorized modifications of protected files or areas within the file system, potentially allowing malicious applications to alter system or user data without proper permissions.

Remediation

Users can update to macOS Ventura 13.7.5, macOS Sequoia 15.4, or macOS Sonoma 14.7.5 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.