Symlink Handling Vulnerability in Apple macOS Tahoe
CVE-2025-43369

5.5MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
15 September 2025

What is CVE-2025-43369?

A symlink handling vulnerability has been identified in Apple macOS Tahoe that could permit unauthorized applications to access protected user data without proper permissions. This flaw compromises the integrity of user privacy and data security. The issue has been resolved with enhanced symlink processing in macOS Tahoe version 26.

Affected Version(s)

macOS < 26

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-43369 : Symlink Handling Vulnerability in Apple macOS Tahoe