CVE-2025-43523
Description
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may be able to access sensitive user data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An app on macOS may access sensitive payment tokens due to a permissions issue, fixed in macOS Sequoia 15.7.3 and Tahoe 26.2.
Vulnerability
Overview A permissions issue in macOS was addressed with additional restrictions. The vulnerability allows an app to access sensitive payment tokens, as described in the vendor security advisories for macOS Sequoia 15.7.3 and macOS Tahoe 26.2. The root cause is a missing or insufficient permission check, which could be bypassed by a malicious application. [1]
Attack
Vector and Prerequisites Exploitation requires a macOS system that has not been updated to the patched versions. An attacker must either trick the user into installing a malicious app or gain code execution through other means. No additional authentication is needed once the app is running on the user's system under the user's privileges. [1][2]
Impact
A successful exploit could allow an app to access sensitive user data, specifically payment tokens that might be stored on the system. This could lead to unauthorized transactions or identity theft. The CVSS v3 base score is 5.5 (Medium), reflecting the need for local access and user interaction. [2]
Mitigation
Apple has released macOS Sequoia 15.7.3 and macOS Tahoe 26.2, which contain the fix for this issue. Users are advised to update their systems via Software Update or Apple's support pages. No workarounds have been published. [1][2]
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: <15.7.3
- Range: <26.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- support.apple.com/en-us/125887nvdRelease NotesVendor Advisory
- support.apple.com/en-us/125886nvd
News mentions
0No linked articles in our index yet.