Junglewise Threat Intelligence

CVE-2025-43403: Apple macOS improper authorization in Compression component

CVE-2025-43403 · Severity: medium · CVSS 5.5 · Published 2026-02-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

An authorization flaw in the macOS Compression component could allow a malicious application to access sensitive user data. This component is responsible for handling file compression and decompression tasks on the system. If exploited, an attacker could bypass security controls to view private information they should not have access to.

Technical details

An improper authorization vulnerability (CWE-285) exists in the Compression component of macOS. The flaw stems from insufficient state management during authorization checks. A local application, potentially requiring user interaction, can exploit this issue to bypass intended access controls and read sensitive user data. Apple addressed the vulnerability by improving state management logic. The fix is available in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.

Affected products

  • Apple macOS Sequoia before 15.7.4
  • Apple macOS Sonoma before 14.8.4
  • Apple macOS Tahoe before 26

Timeline

  • 2025-09-15: patched: Initial fix in macOS Tahoe 26
  • 2026-02-11: advisory: Published for macOS Sequoia and Sonoma

References

Related threats