VYPR
Medium severity5.5NVD Advisory· Published Mar 10, 2025· Updated Apr 2, 2026

CVE-2024-54469

CVE-2024-54469

Description

The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, visionOS 2. A local user may be able to leak sensitive user information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A local user may be able to leak sensitive user information via an app, addressed with improved checks in multiple Apple OS updates.

Vulnerability

Overview

CVE-2024-54469 is a vulnerability in Apple operating systems where a local user or app may be able to leak sensitive user information. The root cause lies in insufficient permission checks, allowing an app to bypass restrictions and access data it should not have access to [1][2][4]. In macOS Sonoma 14.7, the issue is described as improved permissions logic [3].

Exploitation

Exploitation requires local access to the device, either as a user or via a malicious app installed on the system. No network-based attack vector is involved, as the vulnerability is triggered locally. The attacker does not need elevated privileges beyond standard user access; the app can exploit the weak checks to access sensitive information [1][2].

Impact

A successful exploit allows an app to leak sensitive user information, which could include personal data, credentials, or other private details stored on the device. The exact type of information is not specified, but the impact is rated Medium with a CVSS v3 score of 5.5 [1][2][4].

Mitigation

Apple has addressed this vulnerability in the following updates: iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, and visionOS 2. Users are advised to update their devices to the latest available versions to protect against potential exploitation [1][2][3][4].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.