Junglewise Threat Intelligence

CVE-2025-43278: Apple macOS Sequoia Improper Symlink Handling Data Access

CVE-2025-43278 · Severity: info · CVSS 5.5 · Published 2026-06-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A security vulnerability in macOS Sequoia could allow a malicious application to access protected user data. This issue stems from how the operating system handles symbolic links, which are shortcuts to other files. By exploiting this, an app could potentially bypass privacy protections to read sensitive information it should not have access to.

Technical details

A vulnerability exists in macOS Sequoia (prior to version 15.4) related to the improper handling of symbolic links (symlinks). An attacker-controlled application can leverage this flaw to bypass filesystem permissions or sandbox restrictions to access protected user data. The issue was addressed by improving the logic used to resolve and validate symlinks during file operations. Exploitation typically requires a malicious application to be executed on the local system. Apple addressed this in macOS Sequoia 15.4.

Affected products

  • Apple macOS Sequoia Before 15.4

Timeline

  • 2025-03-31: patched: Fixed in macOS Sequoia 15.4
  • 2026-06-11: disclosed: CVE record published

References

Related threats