This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7, macOS Monterey 12.7.5. An app may be able to modify protected parts of the file system.
                
            References
                    | Link | Resource | 
|---|---|
| https://support.apple.com/en-us/HT214105 | Vendor Advisory | 
| https://support.apple.com/en-us/HT214106 | Vendor Advisory | 
| https://support.apple.com/en-us/HT214107 | Vendor Advisory | 
| https://support.apple.com/kb/HT214105 | Vendor Advisory | 
| https://support.apple.com/kb/HT214106 | Vendor Advisory | 
| https://support.apple.com/kb/HT214107 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2024-06-10 21:15
Updated : 2024-07-03 15:44
NVD link : CVE-2024-27885
Mitre link : CVE-2024-27885
CVE.ORG link : CVE-2024-27885
JSON object : View
Products Affected
                apple
- macos
CWE
                
                    
                        
                        CWE-59
                        
            Improper Link Resolution Before File Access ('Link Following')
