CVE Vulnerabilities

CVE-2025-30456

Improper Preservation of Permissions

Published: Mar 31, 2025 | Modified: Nov 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain root privileges.

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

NameVendorStart VersionEnd Version
IpadosApple*18.4 (excluding)
Iphone_osApple*18.4 (excluding)
MacosApple*13.7.5 (excluding)
MacosApple14.0 (including)14.7.5 (excluding)
MacosApple15.0 (including)15.4 (excluding)

References