CVE-2015-7024 describes an untrusted search path vulnerability in Apple OS X before version 10.11.1, allowing local users to bypass Gatekeeper restrictions. An attacker could exploit this by tricking a user into running a Trojan horse program loaded from an unexpected directory by a legitimate, digitally signed application, potentially leading to privilege escalation. With a CVSS score of 6.7 (Medium), this vulnerability requires local access and user interaction, but could result in high impact to confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.11.0CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.