CVE-2025-24204

August 15, 2025 · View on GitHub

About

CVE-2025-24204 is a vulnerability that allows reading any process memory on SIP-enabled macOS systems. The root cause of this vulnerability stems from adding an excessively powerful entitlement (com.apple.system-task-ports.read) to the gcore binary. Exploiting this vulnerability enables:

Author

Koh M. Nakagawa (@tsunek0h). © FFRI Security, Inc. 2025

License

Apache version 2.0