---
id: CVE-2025-24259
title: This issue was addressed with additional entitlement checks
summary: >-
  This issue was addressed with additional entitlement checks. This issue is
  fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura
  13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement
  check.
severity: none
vendor: apple
product: macos
affected:
  - 'macos >= 13.0, < 13.7.5'
  - 'macos >= 14.0, < 14.7.5'
  - 'macos >= 15.0, < 15.4'
patched:
  - macos 15.4
published: '2025-03-31'
updated: '2026-07-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-24259'
references:
  - url: 'https://support.apple.com/en-us/122373'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/122374'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/122375'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/122405'
    label: product-security@apple.com
  - url: 'http://seclists.org/fulldisclosure/2025/Apr/10'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Apr/8'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Apr/9'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/May/6'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00757
epssPercentile: 0.53198
ingestedAt: '2026-07-22T18:05:37.727Z'
---

## Overview

This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.

## Affected

- `macos >= 13.0, < 13.7.5`
- `macos >= 14.0, < 14.7.5`
- `macos >= 15.0, < 15.4`

## Remediation

Upgrade past the affected range:

- `macos 15.4`
