Junglewise Threat Intelligence

CVE-2025-30431: Apple macOS Information Disclosure via Malicious App

CVE-2025-30431 · Severity: info · CVSS 5.5 · Published 2026-06-11

Technologies: Apple macOS Sonoma, Apple macOS Ventura. Vendors: Apple.

Executive brief

A vulnerability in macOS could allow a malicious application installed on a computer to access a user's private information. This could lead to the unauthorized exposure of sensitive personal data. Apple has released software updates to address this issue by improving security checks within the operating system.

Technical details

An information disclosure vulnerability exists in macOS Sequoia, Sonoma, and Ventura. The flaw is caused by insufficient validation checks, which could allow a locally installed malicious application to bypass privacy protections and access sensitive user data. The vulnerability was addressed by implementing improved checks within the affected components. Patches are available in macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5.

Affected products

  • Apple macOS Sequoia Before 15.4
  • Apple macOS Sonoma Before 14.7.5
  • Apple macOS Ventura Before 13.7.5

Timeline

  • 2025-03-31: patched: Initial release of fixes in macOS 15.4, 14.7.5, and 13.7.5.
  • 2026-06-11: disclosed: CVE record published.

References

Related threats