This issue was addressed with improved entitlements. This issue is fixed in macOS Sequoia 15. An app may be able to access removable volumes without user consent.
References
History

Tue, 11 Mar 2025 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved entitlements. This issue is fixed in macOS Sequoia 15. An app may be able to access removable volumes without user consent.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2025-03-10T19:11:10.755Z

Updated: 2025-03-11T02:47:09.447Z

Reserved: 2024-12-03T22:50:35.492Z

Link: CVE-2024-54463

cve-icon Vulnrichment

Updated: 2025-03-11T02:46:49.328Z

cve-icon NVD

Status : Received

Published: 2025-03-10T19:15:38.290

Modified: 2025-03-11T03:15:37.497

Link: CVE-2024-54463

cve-icon Redhat

No data.