Junglewise Threat Intelligence

CVE-2025-43473: Apple macOS sensitive data access vulnerability

CVE-2025-43473 · Severity: medium · CVSS 5.5 · Published 2025-12-12

Technologies: Apple macOS. Vendors: Apple.

Executive brief

An issue in Apple macOS systems may allow apps to access sensitive user data due to improper state management. This could result in unauthorized exposure of private information including user credentials, personal files, and system data. The vulnerability affects multiple macOS versions and can be exploited by a locally-installed application.

Technical details

The vulnerability is a state management issue in macOS that may allow applications to bypass normal access controls and read sensitive user information. The attack requires the app to be installed and running on the affected system (local attack vector). An attacker can leverage improper state handling to access protected data that should be restricted by the operating system's sandbox and permission model. The issue has been addressed through improved state management in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.1.

Affected products

  • Apple macOS Sequoia before 15.7.4
  • Apple macOS Sonoma before 14.8.4
  • Apple macOS Tahoe before 26.1

Timeline

  • 2025-12-12: disclosed: CVE-2025-43473 published
  • 2025-11-03: patched: macOS Tahoe 26.1 released
  • 2026-02-11: patched: macOS Sequoia 15.7.4 released

References

Related threats