CVE-2025-24256
macOS vulnerability analysis and mitigation

Overview

CVE-2025-24256 is a security vulnerability affecting macOS operating systems that was disclosed on March 31, 2025. The vulnerability exists in the GPU Drivers component where an app may be able to disclose kernel memory. This issue affects multiple versions of macOS including Ventura (13.0-13.7.5), Sonoma (14.0-14.7.5), and Sequoia (15.0-15.4) (NVD).

Technical details

The vulnerability is classified as an out-of-bounds read issue (CWE-125) in the GPU Drivers component. It received a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The issue was addressed by Apple through improved bounds checks implementation (NVD).

Impact

The vulnerability allows a malicious application to potentially access and disclose kernel memory, which could lead to the exposure of sensitive system information. This type of vulnerability could potentially be used to bypass system security mechanisms and access protected data (Apple Support).

Exploitability

The vulnerability has a critical severity rating with a CVSS score of 9.8, indicating high exploitability. The attack vector is network-accessible (AV:N), requires low attack complexity (AC:L), needs no privileges (PR:N), and requires no user interaction (UI:N) (NVD).

Mitigation and workarounds

Apple has released security updates to address this vulnerability in macOS Ventura 13.7.5, macOS Sequoia 15.4, and macOS Sonoma 14.7.5. Users are advised to update their systems to these versions or later to mitigate the risk (Apple Support, Apple Support, Apple Support).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86917HIGH7.8
  • macOS logomacOS
  • Kernel
NoYesSep 14, 2026
CVE-2026-86924MEDIUM5.5
  • macOS logomacOS
  • MobileAccessoryUpdater
NoYesSep 14, 2026
CVE-2026-86910MEDIUM5.5
  • macOS logomacOS
  • APFS
NoYesSep 14, 2026
CVE-2026-86902MEDIUM5.5
  • macOS logomacOS
  • NSDocument
NoYesSep 14, 2026
CVE-2026-86891LOW3.5
  • macOS logomacOS
  • Core Bluetooth
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management