Junglewise Threat Intelligence

CVE-2025-46315: Apple macOS Tahoe permissions bypass in Disk Images

CVE-2025-46315 · Severity: info · CVSS 4.3 · Published 2026-06-11

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A security vulnerability in macOS Tahoe could allow a malicious application to bypass privacy protections and access sensitive user data. This issue stems from insufficient permission restrictions within the Disk Images component. Users are advised to update to macOS Tahoe 26.1 to ensure their private information remains protected from unauthorized app access.

Technical details

A permissions issue in the Disk Images framework of macOS Tahoe was identified where insufficient restrictions could allow an application to access protected user data. The vulnerability is categorized as a permissions/access control issue. An attacker would need to entice a user to run a malicious application on the local system to exploit this flaw. Apple addressed the issue in macOS Tahoe 26.1 by implementing additional restrictions and improved validation within the affected component.

Affected products

  • Apple macOS Tahoe Before 26.1

Timeline

  • 2025-11-03: patched: macOS Tahoe 26.1 released
  • 2026-06-11: disclosed: CVE published/updated with specific researcher credit

References

Related threats