ID:11246 - Exploit for Input validation error in macOS - CVE-2024-54525

 
Main Vulnerability Database Exploits ID:11246 - Exploit for Input validation error in macOS - CVE-2024-54525

ID:11246 - Exploit for Input validation error in macOS - CVE-2024-54525

Published: March 25, 2025


Vulnerability identifier: #VU105834
Vulnerability risk: Medium
CVE-ID: CVE-2024-54525
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:
macOS

Link to public exploit:


Vulnerability description

The vulnerability allows an attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input in MobileBackup when restoring data from a backup file. An attacker can trick the victim into restoring data from a specially crafted backup and modify protected system files.


Remediation

Install updates from vendor's website.