CVE-2025-43270
BaseFortify
Publication date: 2025-07-30
Last updated on: 2026-04-02
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | macos | to 13.7.7 (exc) |
| apple | macos | From 14.0 (inc) to 14.7.7 (exc) |
| apple | macos | From 15.0 (inc) to 15.6 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
The vulnerability could allow an application to access the Local Network without proper authorization, potentially leading to unauthorized network interactions or data exposure within the local network environment.
Can you explain this vulnerability to me?
This vulnerability is an access issue where an application may gain unauthorized access to the Local Network. It was addressed by adding additional sandbox restrictions in macOS versions Sequoia 15.6, Ventura 13.7.7, and Sonoma 14.7.7.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update your system to macOS Sequoia 15.6, macOS Ventura 13.7.7, or macOS Sonoma 14.7.7 where the issue is fixed.