CVE-2025-43320 is a local privilege escalation vulnerability affecting Apple macOS, where a malicious application could bypass launch constraint protections to execute code with elevated privileges. Rated with a CVSSv3.1 score of 7.8 (High), this vulnerability has a local attack vector and low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability. The issue was addressed by adding additional logic in macOS Sequoia 15.7.3 and macOS Tahoe 26. There is currently no evidence of active exploitation, nor is public exploit code available through common platforms like Metasploit or ExploitDB. Furthermore, community discussion and media coverage regarding this CVE are minimal, indicating low public awareness or interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.7.3CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 0, < 15.7.3CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* | ||
>= 0, < 26CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.