CVE-2025-31272High· 7.8▾ TwilightThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.
macos < 15.4Upgrade past the affected range:
macos 15.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84587Medium· 5.5A permissions issue was addressed with additional restrictions
CVE-2025-24259NoneThis issue was addressed with additional entitlement checks
CVE-2024-54554Medium· 5.5This issue was addressed with improved handling of symlinks
CVE-2024-54568Medium· 4.3The issue was addressed with improved memory handling
CVE-2024-44271Low· 3.3The issue was addressed with improved checks
CVE-2025-43499Medium· 5.5This issue was addressed with additional entitlement checks