This issue was addressed with improved file handling. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to access sensitive user data.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT214083 | vendor advisory |
https://support.apple.com/en-us/HT214085 | vendor advisory |
https://support.apple.com/en-us/HT214084 | vendor advisory |
http://seclists.org/fulldisclosure/2024/Mar/21 | mailing list |
http://seclists.org/fulldisclosure/2024/Mar/22 | mailing list |
http://seclists.org/fulldisclosure/2024/Mar/23 | mailing list |