Logic Flaw in macOS Products Leading to Unauthorized Root Access
CVE-2025-43249

7.8HIGH

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
30 July 2025

What is CVE-2025-43249?

A logic flaw discovered in multiple versions of macOS could potentially allow an unauthorized application to escalate its privileges to root. This vulnerability underscores the importance of prompt updates and secure software practices. Apple has released updates in macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7 to address and mitigate the risk associated with this issue.

Affected Version(s)

macOS < 15.6

macOS < 14.7

macOS < 13.7

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.