Junglewise Threat Intelligence

CVE-2025-46293: Apple macOS Sequoia improper symlink handling

CVE-2025-46293 · Severity: info · Published 2026-06-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A vulnerability in macOS Sequoia could allow a malicious application to access protected user data. This occurs due to improper handling of symbolic links, which are shortcuts to other files. By exploiting this, an app could bypass standard security restrictions to read sensitive information it should not have access to.

Technical details

A vulnerability exists in macOS Sequoia prior to version 15.4 due to improper handling of symbolic links (symlinks). A local malicious application can exploit this flaw to bypass filesystem permissions or sandbox restrictions, gaining unauthorized access to protected user data. The issue was addressed by Apple through improved symlink handling logic. Successful exploitation requires a malicious app to be executed on the target system.

Affected products

  • Apple macOS Sequoia Before 15.4

Timeline

  • 2025-03-31: patched: Fixed in macOS Sequoia 15.4
  • 2026-06-11: disclosed: NVD publication date

References

Related threats