CVE-2025-24155
Description
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to disclose kernel memory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A memory handling flaw in macOS allows an app to read kernel memory, potentially leaking sensitive data. Patched in macOS Ventura 13.7.6, Sonoma 14.7.6, and Sequoia 15.3.
Vulnerability
Details
CVE-2025-24155 is a kernel memory disclosure vulnerability in macOS that arises from improper memory handling within the operating system. The flaw is present in macOS Ventura, Sonoma, and Sequoia prior to the specified updates, and it can be exploited by an unsandboxed application running on the same device.[1][2][3]
Attack
Vector and Exploitation
An attacker who can execute a malicious or compromised app on the target system can leverage this memory handling issue to read portions of kernel memory. No special privileges beyond app execution are required, and the attack does not require user interaction beyond the initial app execution. The vulnerability is triggered locally, not over the network, and does not rely on network-based attack vectors such as AFP server connections.
Impact
Successful exploitation of CVE-2025-24155 allows an unprivileged app to read kernel memory, which may contain sensitive information such as cryptographic keys, process credentials, or other privileged data. This information disclosure could serve as a stepping stone for further attacks, including privilege escalation or bypassing security mechanisms. The vulnerability is rated Medium (CVSS 5.5) by Apple, reflecting the local access requirement and the potential for significant information leak.
Mitigation
Apple has addressed this issue with improved memory handling in macOS Ventura 13.7.6, macOS Sonoma 14.7.6, and macOS Sequoia 15.3. Users are strongly advised to update to the latest available version for their macOS release. No workarounds have been publicly disclosed, and there is no evidence that this vulnerability is being actively exploited in the wild as of the publication date.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- support.apple.com/en-us/122068nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122717nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122718nvdRelease NotesVendor Advisory
- seclists.org/fulldisclosure/2025/May/8nvd
- seclists.org/fulldisclosure/2025/May/9nvd
News mentions
0No linked articles in our index yet.