CVE Vulnerabilities

CVE-2025-24148

Improper Validation of Integrity Check Value

Published: Mar 31, 2025 | Modified: Dec 26, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

This issue was addressed with improved handling of executable types. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious JAR file may bypass Gatekeeper checks.

Weakness

The product does not validate or incorrectly validates the integrity check values or “checksums” of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Affected Software

NameVendorStart VersionEnd Version
MacosApple*13.7.5 (excluding)
MacosApple14.0 (including)14.7.5 (excluding)
MacosApple15.0 (including)15.4 (excluding)

Potential Mitigations

References