Protection mechanism failure in macOS - CVE-2024-54564

 

Protection mechanism failure in macOS - CVE-2024-54564

Published: March 21, 2025


Vulnerability identifier: #VU105911
CSH Severity: Medium
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-54564
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures. A file received from AirDrop may not have the quarantine flag applied. This can help an attacker into tricking the victim to execute the file, as it will appear as safe for execution.


Affected software

macOS
visionOS
iPadOS
Apple iOS

How to mitigate CVE-2024-54564

Install updates from vendor's website.

macOS - update to 14.6 23G80
visionOS - update to 1.3
iPadOS - update to 17.6 21G80
Apple iOS - update to 17.6 21G80

External References

Related Security Bulletins