CVE-2025-43479
Description
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An app on macOS may be able to access sensitive user data due to a permissions logic issue, fixed in macOS Sequoia 15. 15.7.2, Sonoma 14.8.2, and Tahoe 26.1.
Root
Cause CVE-2025-43479 is a permissions vulnerability in macOS that arises from a logic flaw in the operating system's access controls. The official description notes that the issue was addressed with additional restrictions, while the advisory for macOS Tahoe specifies that the problem was corrected with improved checks [1]. The advisories for macOS Sequoia and Sonoma further describe a logic issue that was resolved with improved checks [2][3].
Exploitation
An attacker would need to convince a user to run a malicious application on an affected Mac. No special privileges or network position are mentioned in the advisories, suggesting that the attack vector is local and user-assisted. The prerequisite is that the app must be executed on a vulnerable version of macOS prior to the fixes released on November 3, 2025.
Impact
Successful exploitation could allow that app to access sensitive user data without proper authorization. The impact is limited to data confidentiality, and Apple rates the severity as Medium with a CVSS v3 base score of 5.5, reflecting a moderate risk to user privacy.
Mitigation
Apple has released patches by updating macOS to Sequoia 15.7.2, Sonoma 14.8.2, and Tahoe 26.1. Users should apply these updates through Software Update or by downloading the full installers from Apple. There is no indication that this vulnerability has been exploited in the wild or included in any government catalog (e.g., KEV).
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: <15.7.2
- Range: <14.8.2
- Range: <26.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- support.apple.com/en-us/125635nvdRelease NotesVendor Advisory
- support.apple.com/en-us/125636nvdRelease NotesVendor Advisory
- support.apple.com/en-us/125634nvd
News mentions
0No linked articles in our index yet.