CVE-2024-54466Missing Authorization in Apple Macos

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 65.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12

Description

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An encrypted volume may be accessed by a different user without prompting for the password.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

CVEListV5apple/macos< 13.7.2+2
NVDapple/macos13.013.7.2+2

🔴Vulnerability Details

1
GHSA
GHSA-77pc-23q5-7vg9: An authorization issue was addressed with improved state management2024-12-12

📋Vendor Advisories

3
Apple
CVE-2024-54466: macOS Sequoia 15.22024-12-11
Apple
CVE-2024-54466: macOSSonoma14.7.22024-12-11
Apple
CVE-2024-54466: macOSVentura13.7.22024-12-11
CVE-2024-54466 — Missing Authorization in Apple Macos | cvebase