Apple Copyfile Symlink Validation Vulnerability Allowing Access to Protected User Data

Vulnerability

A vulnerability exists in the copyfile component of iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7. This vulnerability arises from inadequate validation of symlinks, which may allow an application to access protected user data.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive user data.

Added: Jul 30, 2025, 1:48 AM
Updated: Jul 30, 2025, 1:48 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.7
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.