CVE-2025-24263 Details
Description
A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15.4. An app may be able to observe unprotected user data.
A privacy vulnerability in Apple macOS Sequoia 15.4 has been identified, specifically within the StickerKit component. This issue allows an application to observe sensitive user data that is not adequately protected. The vulnerability arises from insufficient data redaction, which could enable unauthorized access to private information.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://seclists.org/fulldisclosure/2025/Apr/8 | CVE | Third Party Advisory |
| https://support.apple.com/en-us/122373 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apple macos | < 15.4 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 7, 2025 | Modified Analysis | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Apr 4, 2025 | Initial Analysis | [email protected] |
| Apr 1, 2025 | CVE Modified | CISA-ADP |
| Mar 31, 2025 | New CVE Received | [email protected] |