CVE-2025-43188
BaseFortify
Publication date: 2025-07-30
Last updated on: 2025-11-03
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | macos | to 15.6 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a permissions issue in macOS Sequoia 15.6 that could allow a malicious application to gain root privileges by exploiting insufficient restrictions.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow a malicious app to gain root privileges, potentially leading to unauthorized full control over the affected system, including access to protected data and the ability to modify system settings or software.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, you should update your system to macOS Sequoia 15.6, where the issue has been fixed by adding additional permission restrictions to prevent malicious apps from gaining root privileges. [1]