Vulnerability threat dossier

CVE-2024-54529

applemacos

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

VTP deterministic threat20.6of 100 · CVSS excluded

VTP analyst assessment

macOS sandbox escape with public functional exploit

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence88%
Public exploitation · VTP factUNKNOWN

Assessment

Security researchers report a functional exploit for this macOS sandbox-escape and elevated-privilege flaw. No reported attacks or confirmed compromises are supplied.

Why it matters

  • A local app may execute code outside its sandbox or with elevated privileges.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The supplied research establishes public exploit availability, not exploitation in the wild.

We do not know whether affected macOS versions are deployed.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Review in your environment: if you use macOS Ventura 13.7.2, Sonoma 14.7.2, or Sequoia 15.2, check whether the listed fixes are applied.

AI baseline history (1)
  1. BASELINE ASSESSED
    macOS sandbox escape with public functional exploitgpt-5.6-terra · low
Technical severityHIGHCVSS 7.8 · technical context
Public exploitationUNKNOWNGlobal public evidence
Exploit maturityFUNCTIONAL EXPLOITReliability not implied
EPSS0.0026th percentile · prediction
Evidence confidence78%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    Exploit maturity is assessed as functional exploit.

  2. 02

    EPSS is 0.00; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

FUNCTIONAL EXPLOIT AVAILABLEFunctional Exploit Available
RESEARCH PUBLICATIONNew technical research
03

Claim provenance

Evidence and source independence

1publications detected
1underlying evidence chains

1 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimFUNCTIONAL EXPLOIT AVAILABLEPUBLICATION REPORTS FUNCTIONAL EXPLOIT
78%claim confidence
INDEPENDENTreport:29557bf34d74a6b962b67775a23f3d55fa71d190efb57d00418cbfc599a63accACTIVE
Evidence
04

Event history

Threat timeline

  1. 08:0030 Jan
    FUNCTIONAL EXPLOIT AVAILABLE

    Functional Exploit Available

    Google Project Zero supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 08:0030 Jan
    RESEARCH PUBLICATION

    New technical research

    Google Project Zero published evidence linked to CVE-2024-54529.

05

Original publications

Source record

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-54529) and a double-free vulnerability (CVE-2025-31235) in the coreaudiod system daemon through a process I call knowledge-driven fuzzing. While the first post focused on the process of finding the vulnerabilities, this post dives into the intricate process of exploiting the type confusion vulnerability. I’ll explain the technical details of turning a potentially exploitable crash into a working exploit: a journey filled with dead ends, creative problem solving, and ultimately, success. The Vulnerability: A Quick Recap If you haven’t already, I highly recommend reading my detailed writeup on this vulnerability before proceeding. As a refresher, CVE-2024-54529 is a type confusion vulnerability within the com.apple.audio.audiohald Mach service in the CoreAudio framework used by the coreaudiod process. Several Mach message handlers, such as _XIOContext_Fetch_Workgroup_Port, would fetch a HALS_Object from the Object Map based on an ID from the Mach message, and then perform operations on it, assuming it was of a specific type (ioct) without proper validation.

CVE-2024-54529CVE-2025-31235
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score20.6vtp-threat-v1-public
Public exploitation0 / 30
EPSS prediction0.07 / 20
Exploit availability11 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE
CWE-94
CPE records
1
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.