CVE-2025-43523
BaseFortify
Publication date: 2025-12-12
Last updated on: 2026-04-02
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | macos | to 15.7.3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
| CWE-NVD-CWE-noinfo |
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The vulnerability allows an app to access sensitive user data by bypassing intended security restrictions, which could potentially lead to unauthorized data access. This type of issue may impact compliance with data protection standards and regulations such as GDPR and HIPAA that require safeguarding sensitive user information. The fix in macOS Sequoia 15.7.3 adds additional restrictions to prevent such unauthorized access, thereby helping to maintain compliance. [1]
Can you explain this vulnerability to me?
This vulnerability is a permissions issue in macOS Sequoia 15.7.3 where an app may be able to access sensitive user data due to insufficient restrictions.
How can this vulnerability impact me? :
An app exploiting this vulnerability could gain unauthorized access to sensitive user data, potentially compromising your privacy and security.
What immediate steps should I take to mitigate this vulnerability?
Update your system to macOS Sequoia 15.7.3 or later, as this version contains the fix for the permissions issue that could allow an app to access sensitive user data.