CVE-2025-24248: Apple macOS
Medium severity, CVSS 5.0. EPSS: 0.4% chance of exploitation in the next 30 days.
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to enumerate devices that have signed into the user's Apple Account.
Affected products
- Apple macOS: before 15.4 (fixed in 15.4)
Published 2025-03-31. Last modified 2026-06-17.