CVE-2025-24245
published 2025-03-31CVE-2025-24245: This issue was addressed by adding a delay between verification code attempts. This issue is fixed in macOS Sequoia 15.4. A malicious app may be able to access…
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.61%
45.4th percentile
This issue was addressed by adding a delay between verification code attempts. This issue is fixed in macOS Sequoia 15.4. A malicious app may be able to access a user's saved passwords.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 15.4 | 15.4 |
| apple | macos_sequoia | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-crwm-v9wf-m9pg: This issue was addressed by adding a delay between verification code attempts
ghsa_unreviewed·2025-04-01
CVE-2025-24245 [CRITICAL] CWE-862 GHSA-crwm-v9wf-m9pg: This issue was addressed by adding a delay between verification code attempts
This issue was addressed by adding a delay between verification code attempts. This issue is fixed in macOS Sequoia 15.4. A malicious app may be able to access a user's saved passwords.
Apple
CVE-2025-24245: macOS Sequoia 15.4
vendor_apple·2025-03-31·CVSS 9.8
CVE-2025-24245 [CRITICAL] CVE-2025-24245: macOS Sequoia 15.4
Apple Security Update: About the security content of macOS Sequoia 15.4
Product: macOS Sequoia
Version: 15.4
CVE: CVE-2025-24245
Component: Authentication Services
Impact: A malicious app may be able to access a user's saved passwords
Description: This issue was addressed by adding a delay between verification code attempts.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-31
Published