CVE Vulnerabilities

CVE-2024-44280

Published: Oct 28, 2024 | Modified: Dec 11, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An app may be able to modify protected parts of the file system.

Affected Software

Name Vendor Start Version End Version
Macos Apple 13.0 (including) 13.7.1 (excluding)
Macos Apple 14.0 (including) 14.7.1 (excluding)

References