This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, visionOS 2.1, macOS Sonoma 14.7.1, watchOS 11.1, tvOS 18.1. A malicious app may be able to access private information.
CVE ID: CVE-2024-44273
CVSS Base Severity: LOW
CVSS Base Score: 0.0
Vendor: Apple
Product: macOS
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 23.51% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)