CVE-2024-54489: Apple macOS

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. Running a mount command may unexpectedly execute arbitrary code.

Affected products

  • Apple macOS: before 13.7.2 (fixed in 13.7.2); from 14.0, before 14.7.2 (fixed in 14.7.2); from 15.0, before 15.2 (fixed in 15.2)

Published 2024-12-12. Last modified 2026-06-17.