Apple macOS Symlink Validation Vulnerability Allowing Access to Protected User Data

Vulnerability

A vulnerability exists in the handling of symbolic links in various macOS versions, including Ventura 13.7.5, Sequoia 15.4, and Sonoma 14.7.5. This vulnerability allows applications to access sensitive user data by exploiting inadequate validation of symlinks.

Impact

Exploitation of this vulnerability could lead to unauthorized access to protected user data.

Remediation

Users can update to macOS Ventura 13.7.5, macOS Sequoia 15.4, or macOS Sonoma 14.7.5 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.