CVE-2025-43396 is a logic issue in Apple macOS that could allow a sandboxed application to bypass security restrictions and access sensitive user data. This vulnerability affects macOS versions prior to Sequoia 15.7.2, Sonoma 14.8.2, and Tahoe 26.1. Rated with a CVSS score of 5.5 (Medium), exploitation requires local access and user interaction, typically through a malicious sandboxed application, leading to a high confidentiality impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion or media coverage for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 14.0, < 14.8.2CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.7.2CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 0, < 14.8.2CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* | ||
>= 0, < 15.7.2CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* | ||
>= 0, < 26.1CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.