CVE-2024-44243
published 2024-12-12CVE-2024-44243: A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.3. An app may be able to modify…
PriorityP423medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
0.58%
43.5th percentile
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.3. An app may be able to modify protected parts of the file system.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 14.7.3 | 14.7.3 |
| apple | macos | < 15.2 | 15.2 |
| apple | macos | >= 15.0 < 15.2 | 15.2 |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2024-44243: macOS Sonoma 14.7.3
vendor_apple·2025-01-27·CVSS 5.5
CVE-2024-44243 [MEDIUM] CVE-2024-44243: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2024-44243
Component: StorageKit
Impact: An app may be able to modify protected parts of the file system
Description: A configuration issue was addressed with additional restrictions.
Apple
CVE-2024-44243: macOS Sequoia 15.2
vendor_apple·2024-12-11·CVSS 5.5
CVE-2024-44243 [MEDIUM] CVE-2024-44243: macOS Sequoia 15.2
Apple Security Update: About the security content of macOS Sequoia 15.2
Product: macOS Sequoia
Version: 15.2
CVE: CVE-2024-44243
Component: StorageKit
Impact: An app may be able to modify protected parts of the file system
Description: A configuration issue was addressed with additional restrictions.
GHSA
GHSA-j3cp-346p-h999: A configuration issue was addressed with additional restrictions
ghsa_unreviewed·2024-12-12
CVE-2024-44243 [MEDIUM] GHSA-j3cp-346p-h999: A configuration issue was addressed with additional restrictions
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2. An app may be able to modify protected parts of the file system.
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
blogs_bleepingcomputer·2025-07-28·CVSS 7.1
CVE-2020-9771 [HIGH] Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
## Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
## Sergiu Gatlan
Since 2020, Apple has patched other TCC bypasses that exploit Time Machine mounts ( CVE-2020-9771 ), environment variable poisoning ( CVE-2020-9934 ), and a bundle conclusion issue ( CVE-2021-30713 ) . In the past, Microsoft security researchers have also discovered several other TCC bypasses, including powerdir ( CVE-2021-30970 ) and HM-Surf , that could also be abused to gain access to users' private data.
"While similar to prior TCC bypasses like HM-Surf and powerdir, the implications of this vulnerability, which we refer to as 'Sploitlight' for its use of Spotlight plugins, are more severe due to its ability to extract and leak sensitive information cached by Apple Intelligence, such as precise geol
Microsoft
Analyzing CVE-2024-44243, a macOS System Integrity Protection bypass through kernel extensions | Microsoft Security Blog
blogs_microsoft·2025-01-13·CVSS 5.5
CVE-2024-44243 [MEDIUM] Analyzing CVE-2024-44243, a macOS System Integrity Protection bypass through kernel extensions | Microsoft Security Blog
- Research
- January 13, 2025
- 9 min read
# Analyzing CVE-2024-44243, a macOS System Integrity Protection bypass through kernel extensions
By Microsoft Threat Intelligence
/
1x
Powered by Microsoft Copilot
Bleepingcomputer
Microsoft: macOS bug lets hackers install malicious kernel drivers
blogs_bleepingcomputer·2025-01-13·CVSS 5.5
CVE-2024-44243 [MEDIUM] Microsoft: macOS bug lets hackers install malicious kernel drivers
## Microsoft: macOS bug lets hackers install malicious kernel drivers
## Sergiu Gatlan
"System Integrity Protection (SIP) serves as a critical safeguard against malware, attackers, and other cybersecurity threats, establishing a fundamental layer of protection for macOS systems," Microsoft said today in a report that provides more technical details on CVE-2024-44243.
"Bypassing SIP impacts the entire operating system's security and could lead to severe consequences, emphasizing the necessity for comprehensive security solutions that can detect anomalous behavior from specially entitled processes."
Microsoft security researchers have discovered multiple macOS vulnerabilities in recent years. A SIP bypass dubbed 'Shrootless ' ( CVE-2021-30892 ), reported in 2021, also allows attackers to
Microsoft
Analyzing CVE-2024-44243, a macOS System Integrity Protection bypass through kernel extensions
blogs_microsoft·2025-01-13·CVSS 5.5
[MEDIUM] Analyzing CVE-2024-44243, a macOS System Integrity Protection bypass through kernel extensions
Research
January 13, 2025
## Related posts
March 12
March 12
March 11
## Get started with Microsoft Security
Protect your people, data, and infrastructure with AI-powered, end-to-end security from Microsoft.
Connect with us on social
Careers
About Microsoft
Company news
Privacy at Microsoft
Investors
Diversity and inclusion
Accessibility
Sustainability
2024-12-12
Published