Permissions, Privileges, and Access Controls in macOS - CVE-2024-54542
Published: March 18, 2025
Vulnerability identifier: #VU105823
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-54542
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to incorrect state management in Safari. Private Browsing tabs may be accessed without authentication.
Affected software
macOS
watchOS
iPadOS
Apple iOS
Apple Safari
watchOS
iPadOS
Apple iOS
Apple Safari
How to mitigate CVE-2024-54542
Install updates from vendor's website.
macOS - update to 15.2 24C101
Apple Safari - update to 18.2
watchOS - update to 11.2
iPadOS - update to 18.2 22C152
Apple iOS - update to 18.2 22C152
Apple Safari - update to 18.2
watchOS - update to 11.2
iPadOS - update to 18.2 22C152
Apple iOS - update to 18.2 22C152