Apple UserAccountUpdater Directory Path Handling Vulnerability Allowing Data Access

Vulnerability

A vulnerability exists in the UserAccountUpdater component of macOS Ventura 13.7.3, macOS Sequoia 15.5, and macOS Sonoma 14.7.3. This vulnerability arises from a parsing issue related to directory paths, which could allow an application to access sensitive user data. The problem has been addressed in the mentioned macOS versions through improved path validation.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by an application.

Added: Nov 21, 2025, 10:25 PM
Updated: Nov 21, 2025, 10:25 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
1.1
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.