CVE-2025-30448

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sonoma 14.7.6, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, visionOS 2.5, macOS Ventura 13.7.6, macOS Sequoia 15.4. An attacker may be able to turn on sharing of an iCloud folder without authentication.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
appleCNA
---
---
CISA-ADPADP
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
VendorProductVersion
appleipados
𝑥
< 17.7.7
appleipados
18.0 ≤
𝑥
< 18.5
appleiphone_os
𝑥
< 18.5
applemacos
𝑥
< 13.7.6
applemacos
14.0 ≤
𝑥
< 14.7.6
applemacos
15.0 ≤
𝑥
< 15.4
applevisionos
𝑥
< 2.5
𝑥
= Vulnerable software versions