CVE-2025-43410
BaseFortify
Publication date: 2025-12-12
Last updated on: 2026-04-02
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | macos | to 14.8.2 (exc) |
| apple | macos | From 15.0 (inc) to 15.7.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-524 | The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves improper handling of caches in macOS, which could allow an attacker with physical access to view deleted notes. The issue has been fixed in macOS Sequoia 15.7.2 and macOS Sonoma 14.8.2 by improving cache handling.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow someone with physical access to your device to view notes that you have deleted, potentially exposing sensitive or private information.
What immediate steps should I take to mitigate this vulnerability?
Update your macOS system to macOS Sequoia 15.7.2 or macOS Sonoma 14.8.2 or later, as these versions include the fix for this vulnerability.