Race Condition Vulnerability in Apple macOS Products
CVE-2025-43420

4.7MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
4 November 2025

What is CVE-2025-43420?

A race condition vulnerability enables unauthorized access to sensitive user data within specific versions of macOS. This flaw has been addressed with improved state handling in recent updates to macOS Sonoma and macOS Sequoia. Users are encouraged to update their systems to the latest versions to mitigate exposure and protect their sensitive information.

Affected Version(s)

macOS < 14.8

macOS < 15.7

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.