Symlink Handling Vulnerability in macOS Sequoia by Apple
CVE-2025-43257

8.7HIGH

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
2 April 2026

What is CVE-2025-43257?

A symlink handling issue has been discovered in macOS Sequoia, allowing applications to potentially escape their designated sandbox environments. This vulnerability could enable unauthorized access to system resources, compromising data integrity and user privacy. The issue has been addressed in version 15.6 of macOS Sequoia, underscoring the importance of applying updates promptly.

Affected Version(s)

macOS 0 < 15.6

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.