CVE-2025-43316
BaseFortify
Publication date: 2025-09-15
Last updated on: 2026-04-02
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | macos | to 26.0 (exc) |
| apple | visionos | to 26.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a permissions issue in Apple operating systems (macOS Tahoe 26 and visionOS 26) where a malicious application could exploit the flaw to gain root privileges, meaning it could obtain the highest level of access on the system.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow a malicious app to gain root privileges, potentially leading to unauthorized control over the affected device, compromising system security and user data.
What immediate steps should I take to mitigate this vulnerability?
Apply the fixed updates for macOS Tahoe 26 and visionOS 26 as soon as they are available to address the permissions issue and prevent malicious apps from gaining root privileges.