CVE-2025-43298 is a high-severity path validation vulnerability affecting Apple macOS, stemming from a parsing issue in directory path handling. This flaw (CVSS 7.8) allows a local attacker with low privileges and complexity to potentially gain root privileges, leading to high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or inclusion in the CISA KEV catalog, Apple has addressed this issue with improved path validation in macOS Sequoia 15.7, macOS Sonoma 14.8, and macOS Tahoe 26.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 14.0, < 14.8CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.7CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 0, < 14.8CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* | ||
>= 0, < 15.7CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* | ||
>= 0, < 26CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.