Junglewise Threat Intelligence

CVE-2025-43417: Apple macOS File Bookmark path handling issue

CVE-2025-43417 · Severity: medium · CVSS 5.5 · Published 2026-02-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A path handling vulnerability in Apple's File Bookmark system allows malicious apps to access user-sensitive data by bypassing proper file access restrictions. This affects macOS Sequoia, Sonoma, and Tahoe, enabling attackers to circumvent sandbox protections and read files they should not have access to. The issue is fixed in patched versions of these operating systems.

Technical details

CVE-2025-43417 is a path handling logic issue in the File Bookmark component of macOS that enables unauthorized access to user-sensitive data. The vulnerability stems from improper validation of file paths, allowing a malicious app to break out of or bypass sandbox restrictions and access protected user files. The issue is local (requires a malicious app to be installed and executed) and can be exploited without authentication. The vulnerability has been addressed with improved path handling logic and is patched in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.2.

Affected products

  • Apple macOS Sequoia 15.7.3 and earlier
  • Apple macOS Sonoma 14.8.3 and earlier
  • Apple macOS Tahoe 26.1 and earlier

Timeline

  • 2026-02-11: disclosed
  • 2026-02-11: patched: Fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.2

References

Related threats