Executive brief
A vulnerability in macOS could allow a malicious application to modify protected parts of the file system. This bypasses standard security restrictions designed to keep core system files safe from unauthorized changes. If exploited, this could lead to unauthorized system modifications or the compromise of system integrity.
Technical details
A permissions vulnerability exists within the CoreServices component of macOS. The flaw allows a local application to bypass file system protections and modify restricted directories or files. Apple addressed this issue by implementing additional restrictions and improved validation within CoreServices. The vulnerability is tracked as CVE-2025-43290 and affects macOS Sequoia versions prior to 15.7, macOS Sonoma versions prior to 14.8, and macOS Tahoe versions prior to 26. Successful exploitation requires a malicious app to be executed on the target system.
Affected products
- Apple macOS Sequoia before 15.7
- Apple macOS Sonoma before 14.8
- Apple macOS Tahoe before 26
Timeline
- 2025-09-15: patched: Initial release of patches for Sequoia 15.7, Sonoma 14.8, and Tahoe 26.
- 2026-05-26: disclosed: Advisory published/updated with CVE details.