Skip to content
Appaloosa Scout

macOS

72 CVEs fixed by this release.

Release date
2025-01-27
End of support
CVEs fixed
72
CISA KEV
1
Critical
0
High
2
NVD pending
70

CVEs fixed

CVE Severity
CVE-2025-24085
KEV

[Apple CoreMedia] A malicious application may be able to elevate privileges. Apple is aware of a report that this issue…

N/A
CVE-2024-55549

xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue

HIGH 7.8
CVE-2025-24855

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can…

HIGH 7.8
CVE-2025-24119

[Apple LaunchServices] An app may be able to execute arbitrary code out of its sandbox or with certain elevated privile…

N/A
CVE-2025-24111

[Apple Display] An app may be able to cause unexpected system termination

N/A
CVE-2025-24144

[Apple Kernel] An app may be able to leak sensitive kernel state

N/A
CVE-2025-24155

[Apple WebContentFilter] An app may be able to disclose kernel memory

N/A
CVE-2025-24113

[Apple Safari] Visiting a malicious website may lead to user interface spoofing

N/A
CVE-2025-24126

[Apple AirPlay] An attacker on the local network may be able to corrupt process memory

N/A
CVE-2025-24129

[Apple AirPlay] An attacker on the local network may cause an unexpected app termination

N/A
CVE-2025-24131

[Apple AirPlay] An attacker on the local network may be able to cause a denial-of-service

N/A
CVE-2025-24139

[Apple sips] Parsing a maliciously crafted file may lead to an unexpected app termination

N/A
CVE-2025-24163

[Apple CoreAudio] Parsing a file may lead to an unexpected app termination

N/A
CVE-2025-24177

[Apple AirPlay] An attacker on the local network may be able to cause a denial-of-service

N/A
CVE-2025-24179

[Apple AirPlay] An attacker on the local network may be able to cause a denial-of-service

N/A
CVE-2025-24086

[Apple ImageIO] Processing an image may lead to a denial-of-service

N/A
CVE-2025-24087

[Apple AppKit] An app may be able to access protected user data

N/A
CVE-2025-24092

[Apple TV App] An app may be able to read sensitive location information

N/A
CVE-2025-24094

[Apple LaunchServices] An app may be able to access user-sensitive data

N/A
CVE-2025-24096

[Apple NSDocument] A malicious app may be able to access arbitrary files

N/A
CVE-2025-24099

[Apple PackageKit] A local attacker may be able to elevate their privileges

N/A
CVE-2025-24100

[Apple AppleMobileFileIntegrity] An app may be able to access information about a user's contacts

N/A
CVE-2025-24101

[Apple Messages] An app may be able to access user-sensitive data

N/A
CVE-2025-24102

[Apple CoreRoutine] An app may be able to determine a user’s current location

N/A
CVE-2025-24103

[Apple Security] An app may be able to access protected user data

N/A
CVE-2025-24106

[Apple Audio] An app may be able to cause unexpected system termination

N/A
CVE-2025-24107

[Apple Kernel] A malicious app may be able to gain root privileges

N/A
CVE-2025-24108

[Apple SharedFileList] An app may be able to access protected user data

N/A
CVE-2025-24109

[Apple AppleMobileFileIntegrity] An app may be able to access sensitive user data

N/A
CVE-2025-24112

[Apple AppleGraphicsControl] Parsing a file may lead to an unexpected app termination

N/A
CVE-2025-24114

[Apple AppleMobileFileIntegrity] An app may be able to modify protected parts of the file system

N/A
CVE-2025-24115

[Apple LaunchServices] An app may be able to read files outside of its sandbox

N/A
CVE-2025-24116

[Apple LaunchServices] An app may be able to bypass Privacy preferences

N/A
CVE-2025-24117

[Apple LaunchServices] An app may be able to fingerprint the user

N/A
CVE-2025-24118

[Apple Kernel] An app may be able to cause unexpected system termination or write kernel memory

N/A
CVE-2025-24120

[Apple WindowServer] An attacker may be able to cause unexpected app termination

N/A
CVE-2025-24121

[Apple AppleMobileFileIntegrity] An app may be able to modify protected parts of the file system

N/A
CVE-2025-24122

[Apple AppleMobileFileIntegrity] An app may be able to modify protected parts of the file system

N/A
CVE-2025-24123

[Apple CoreMedia] Parsing a file may lead to an unexpected app termination

N/A
CVE-2025-24124

[Apple CoreMedia] Parsing a file may lead to an unexpected app termination

N/A
CVE-2025-24127

[Apple ARKit] Parsing a file may lead to an unexpected app termination

N/A
CVE-2025-24128

[Apple Safari] Visiting a malicious website may lead to address bar spoofing

N/A
CVE-2025-24130

[Apple PackageKit] An app may be able to modify protected parts of the file system

N/A
CVE-2025-24134

[Apple FaceTime] An app may be able to access user-sensitive data

N/A
CVE-2025-24135

[Apple System Extensions] An app may be able to gain elevated privileges

N/A
CVE-2025-24136

[Apple Login Window] A malicious app may be able to create symlinks to protected regions of the disk

N/A
CVE-2025-24137

[Apple AirPlay] An attacker on the local network may corrupt process memory

N/A
CVE-2025-24138

[Apple Spotlight] A malicious application may be able to leak sensitive user information

N/A
CVE-2025-24140

[Apple iCloud] Files downloaded from the internet may not have the quarantine flag applied

N/A
CVE-2025-24143

[Apple WebKit] A maliciously crafted webpage may be able to fingerprint the user

N/A
CVE-2025-24145

[Apple Time Zone] An app may be able to view a contact's phone number in system logs

N/A
CVE-2025-24146

[Apple Photos Storage] Deleting a conversation in Messages may expose user contact information in system logging

N/A
CVE-2025-24149

[Apple SceneKit] Parsing a file may lead to disclosure of user information

N/A
CVE-2025-24150

[Apple WebKit Web Inspector] Copying a URL from Web Inspector may lead to command injection

N/A
CVE-2025-24151

[Apple SMB] An app may be able to cause unexpected system termination or corrupt kernel memory

N/A
CVE-2025-24152

[Apple SMB] An app may be able to cause unexpected system termination or corrupt kernel memory

N/A
CVE-2025-24153

[Apple SMB] An app with root privileges may be able to execute arbitrary code with kernel privileges

N/A
CVE-2025-24154

[Apple WebContentFilter] An attacker may be able to cause unexpected system termination or corrupt kernel memory

N/A
CVE-2025-24156

[Apple Xsan] An app may be able to elevate privileges

N/A
CVE-2025-24158

[Apple WebKit] Processing web content may lead to a denial-of-service

N/A
CVE-2025-24159

[Apple Kernel] An app may be able to execute arbitrary code with kernel privileges

N/A
CVE-2025-24160

[Apple CoreAudio] Parsing a file may lead to an unexpected app termination

N/A
CVE-2025-24161

[Apple CoreAudio] Parsing a file may lead to an unexpected app termination

N/A
CVE-2025-24162

[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2025-24169

[Apple Passwords] A malicious app may be able to bypass browser extension authentication

N/A
CVE-2025-24174

[Apple iCloud Photo Library] An app may be able to bypass Privacy preferences

N/A
CVE-2025-24176

[Apple StorageKit] A local attacker may be able to elevate their privileges

N/A
CVE-2025-24183

[Apple Perl] A local user may be able to modify protected parts of the file system

N/A
CVE-2025-24184

[Apple CoreMedia Playback] An app may be able to cause unexpected system termination

N/A
CVE-2025-24185

[Apple sips] Parsing a maliciously crafted file may lead to an unexpected app termination

N/A
CVE-2025-24189

[Apple WebKit] Processing maliciously crafted web content may lead to memory corruption

N/A
CVE-2025-31262

[Apple PackageKit] An app may be able to modify protected parts of the file system

N/A