CVE-2025-24204 is an insufficient-checks vulnerability in the macOS Sequoia kernel that could allow an application to access protected user data. Apple corrected the issue by improving checks in macOS Sequoia 15.4.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a FairPlay decryptor tool for iOS applications running on macOS 15.0-15.2, leveraging CVE-2025-24204. The exploit targets a vulnerability in the gcore utility, which, if it possesses the com.apple.system-task-ports.read entitlement, allows an attacker to dump the memory of running App Store iOS applications and extract their decrypted binaries. The repository includes a SwiftUI-based GUI (ContentView.swift, decryptedApp.swift) for user interaction, and Python scripts (app_scanner.py, decrypt_fairplay.py) that automate the scanning of installed applications, detection of FairPlay encryption, process launching, memory dumping, and binary patching. The setup.py script checks for system compatibility, required tools (radare2, Python dependencies), and makes the scripts executable. The decrypted.entitlements file specifies the necessary macOS entitlements for file and preference access. The tool is operational, requiring local access and administrator privileges, and is intended for use on systems with the vulnerable gcore binary. No network endpoints are involved; all actions are performed locally on the target machine.
This repository provides operational exploit code for CVE-2025-24204, a vulnerability in macOS (15.0-15.2) that allows arbitrary process memory reading due to an overly permissive entitlement (com.apple.system-task-ports.read) granted to the gcore binary. The repository is organized into three main exploit modules: 1. bypass-tcc: Python code to bypass macOS TCC (Transparency, Consent, and Control) privacy protections, enabling extraction of sensitive data such as contacts, browser history, and files from protected applications. It uses process memory dumping and pattern/file-based searches to extract data. 2. decrypt-fairplay: Python code to decrypt FairPlay-encrypted iOS applications on Apple Silicon Macs by dumping and patching process memory, allowing analysis of protected iOS apps. 3. decrypt-keychain: Python code to extract and decrypt the login keychain database without requiring the user's login password, by dumping and analyzing the memory of the securityd process. All modules require root privileges and are intended for use on vulnerable, unpatched macOS systems. The code leverages local process memory access, with no remote/network attack vector. The repository includes detailed technical documentation and usage instructions for each module. Key fingerprintable endpoints include various core dump files in /tmp, the login keychain database, and specific application/process paths targeted for exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.