Junglewise Threat Intelligence

CVE-2025-43238: Apple macOS integer overflow system termination

CVE-2025-43238 · Severity: medium · CVSS 6.2 · Published 2026-04-02

Technologies: Apple macOS Sonoma, Apple macOS Ventura. Vendors: Apple.

Executive brief

A vulnerability in macOS could allow a malicious application to cause the entire computer to crash or shut down unexpectedly. This affects users running older versions of macOS Ventura, Sonoma, and Sequoia. To prevent potential service disruptions or data loss from sudden system restarts, users should update to the latest available software versions.

Technical details

An integer overflow vulnerability (CWE-190) exists in macOS due to insufficient input validation. A local application can exploit this flaw to trigger a kernel panic or unexpected system termination, leading to a denial-of-service (DoS) condition. The vulnerability is reachable without specific user interaction or elevated privileges. Apple addressed the issue by improving input validation in macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7.

Affected products

  • Apple macOS Sequoia before 15.6
  • Apple macOS Sonoma before 14.7.7
  • Apple macOS Ventura before 13.7.7

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory
  • 2026-04-02: patched

References

Related threats