CVE-2025-43241
Description
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to read files outside of its sandbox.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An app may bypass macOS sandbox restrictions to read arbitrary files, patched in macOS Sequoia 15.6, Sonoma 14.7.7, and Ventura 13.7.7.
Vulnerability
Details
CVE-2025-43241 is a permissions bypass that allows an app to read files outside its sandbox. Apple’s advisory states the issue was addressed “with additional restrictions,” though no root-cause details have been published. The fix is included in macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7 [1][2][3].
Exploitation
The vulnerability can be exploited by any application running on a vulnerable macOS version. No special privileges or user interaction beyond launching the malicious app are required. By exploiting the flawed permission checks, an app can escape its sandbox container and access files that should be off-limits [1][2][3].
Impact
A successful exploit gives the attacker read access to sensitive system or user files outside the app’s sandbox, potentially bypassing macOS’s primary security control for untrusted software. Apple rated the issue as Medium severity (CVSS v3.1 score 5.5) and did not indicate evidence of active exploitation [1][2][3].
Mitigation
All three affected macOS versions have been patched. Users should update to the latest minor version from System Settings. No workaround is available. Apple does not list this CVE on the Known Exploited Vulnerabilities catalog [1][2][3].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: <15.6
- Range: <14.7.7
- Range: <13.7.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- support.apple.com/en-us/124149nvdRelease NotesVendor Advisory
- support.apple.com/en-us/124150nvdRelease NotesVendor Advisory
- support.apple.com/en-us/124151nvdRelease NotesVendor Advisory
- seclists.org/fulldisclosure/2025/Jul/32nvd
- seclists.org/fulldisclosure/2025/Jul/33nvd
- seclists.org/fulldisclosure/2025/Jul/34nvd
News mentions
0No linked articles in our index yet.