Junglewise Threat Intelligence

CVE-2025-43451: Apple macOS Tahoe permissions issue allows sensitive data access

CVE-2025-43451 · Severity: info · CVSS 0 · Published 2026-05-26

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A security vulnerability in macOS could allow a malicious application to access sensitive user data without proper authorization. This issue stems from a permissions flaw in the operating system's handling of certain internal components. If exploited, an attacker could bypass privacy protections to steal personal information or monitor user activity. Apple has addressed this by removing the affected code in macOS Tahoe 26.

Technical details

A permissions vulnerability exists in macOS Tahoe prior to version 26. The flaw allowed a locally installed application to bypass intended access controls and retrieve sensitive user data. The root cause was a permissions issue within an unspecified component, which Apple resolved by removing the vulnerable code entirely. Exploitation requires a malicious app to be running on the target system. Users are advised to update to macOS Tahoe 26 or later to mitigate this risk.

Affected products

  • Apple macOS Tahoe before 26

Timeline

  • 2025-09-15: patched: macOS Tahoe 26 released
  • 2026-05-26: disclosed: NVD publication date

References

Related threats