Logic Issue in Apple macOS Products Exposes User Data
CVE-2025-43396

5.5MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
4 November 2025

What is CVE-2025-43396?

A logic issue has been identified in macOS products, which may allow a sandboxed application to gain access to sensitive user data. This vulnerability has been addressed with enhanced checks in the latest updates for macOS Sonoma 14.8.2 and macOS Sequoia 15.7.2. Users are encouraged to update their systems to protect sensitive information from potential exploitation.

Affected Version(s)

macOS < 14.8

macOS < 15.7

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.