CVE-2025-24139: The issue was addressed with improved checks.
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, macOS Ventura 13.7.5. Parsing a maliciously crafted file may lead to an unexpected app termination.
Security readout for executives and security teams
Plain-English summary
CVE-2025-24139 is an Apple macOS file-parsing issue. If a user opens a maliciously crafted file, an app may unexpectedly terminate. Apple addressed it with improved checks in listed macOS security updates. The provided sources do not show active exploitation.
Executive priority
Prioritize routine-to-urgent patching for macOS fleets, particularly user workstations exposed to external files. The issue requires user interaction, but Apple rates the impact high through CVSS metrics.
Technical view
Apple describes this as CWE-787, fixed with improved checks. CVSS 3.1 is 7.8: local attack vector, low complexity, no privileges, user interaction required, and high CIA impact. Public detail is limited to malicious file parsing causing unexpected app termination.
Likely exposure
Organizations with Macs running affected macOS releases before Apple’s listed fixes may be exposed, especially where users handle external, emailed, downloaded, or shared files. The affected product is macOS; the sources do not identify a narrower component.
Exploitation context
Exploitation requires user interaction with a maliciously crafted file on a vulnerable Mac. No CISA KEV listing is present in the provided data, and the cited sources do not claim active exploitation.
Researcher notes
Public technical information is sparse. The CVE identifies CWE-787 and file parsing, but not the exact parser, file format, crash condition, or exploitability beyond Apple’s summary. Avoid assuming code execution or active exploitation without additional sourced evidence.
Mitigation direction
Update macOS to Sequoia 15.3, Sonoma 14.7.3, or Ventura 13.7.3/13.7.5 as applicable.
Review Apple advisories for the correct update path for each managed Mac.
Use MDM to enforce macOS security update compliance.
Reduce exposure to untrusted file attachments and downloads until systems are updated.
Validation and detection
Inventory macOS versions across managed and unmanaged Macs.
Confirm systems meet or exceed Apple’s fixed versions listed for this CVE.
Check MDM or endpoint telemetry for update installation success.
Review Apple support pages for any later guidance or superseding updates.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-787: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
2ADP providers
5Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-787 · source CWE mapping
Out-of-bounds Write
Out-of-bounds Write represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.