Protection Mechanism Failure in macOS - CVE-2025-24172

 

Protection Mechanism Failure in macOS - CVE-2025-24172

Published: April 2, 2025


Vulnerability identifier: #VU106873
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-24172
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an error in the "Block All Remote Content" feature in Mail, which may not apply for al mail previews. A remote attacker can gain access to sensitive information when the victim opens a specially crafted email message. 


Affected software

macOS

How to mitigate CVE-2025-24172

Install updates from vendor's website.

macOS - addressed in versions 15.4 24E248, 13.7.5 22H527, 14.7.5 23H527

External References

Related Security Bulletins