VYPR
Medium severity5.5NVD Advisory· Published Sep 15, 2025· Updated Apr 2, 2026

CVE-2025-31268

CVE-2025-31268

Description

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access protected user data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A permissions issue in macOS allows an app to access protected user data; fixed in macOS Sequoia 15.7, Sonoma 14.8, and Tahoe 26.

CVE-2025-31268 is a permissions vulnerability in macOS that could allow an app to access protected user data. The root cause is a permissions issue that was addressed with additional restrictions in the affected operating system versions [1][3][4].

An attacker would need to have an app installed on the system to exploit this vulnerability. No user interaction beyond normal app execution is required, and the attack surface is local, meaning the app must be running on the target Mac. The exact mechanism of the permissions bypass is not publicly detailed, but it involves insufficient restrictions on accessing protected data.

Successful exploitation could lead to unauthorized access to sensitive user information, such as documents, contacts, or other data protected by macOS privacy controls. The impact is limited to data exposure; no system compromise or code execution is indicated.

Apple has addressed this issue in macOS Sequoia 15.7, macOS Sonoma 14.8, and macOS Tahoe 26. Users are advised to update to the latest available version for their Mac model to mitigate the risk [1][3][4].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.