Description
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. Account-driven User Enrollment may still be possible with Lockdown Mode turned on.
Published: 2025-07-29
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Account Enrollment
Action: Apply Upgrade
AI Analysis

Impact

Apple macOS has a configuration issue that was mitigated with additional restrictions, but account‑driven User Enrollment can still occur when Lockdown Mode is enabled. Based on the description, it is inferred that an attacker could create new user accounts and, through those accounts, potentially install software or achieve elevated privileges that Lockdown Mode is designed to prevent. The weakness is a classic Access Control flaw (CWE‑284).

Affected Systems

Apple macOS versions prior to Sequoia 15.6 and Sonoma 14.7.7. The issue was addressed in those releases, but earlier versions remain vulnerable. All affected macOS installations should be considered at risk if they run an older release.

Risk and Exploitability

The CVSS score of 9.8 marks this as critical, yet the EPSS score of less than 1% suggests very low current exploitation probability. Because it is not listed in CISA’s KEV catalog, there are no confirmed widespread attacks. Based on the description, it is inferred that the attack would be local, requiring improper configuration of Lockdown Mode and account‑enrollment settings, and could potentially be leveraged by a malicious user who gains initial access to the system.

Generated by OpenCVE AI on April 28, 2026 at 11:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the operating system to macOS Sequoia 15.6 or macOS Sonoma 14.7.7 to apply the vendor’s fix.
  • Disable the Account‑driven User Enrollment feature if it is not required for your organization’s workflow.
  • Ensure Lockdown Mode is correctly enabled and verify that its settings prevent unwanted account enrollment.

Generated by OpenCVE AI on April 28, 2026 at 11:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-23129 A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. Account-driven User Enrollment may still be possible with Lockdown Mode turned on.
History

Tue, 28 Apr 2026 11:30:00 +0000

Type Values Removed Values Added
Title Account‑driven User Enrollment possible with Lockdown Mode on macOS

Mon, 03 Nov 2025 20:30:00 +0000


Thu, 31 Jul 2025 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Thu, 31 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 31 Jul 2025 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 31 Jul 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Apple sequoia
Apple sonoma
Vendors & Products Apple
Apple macos
Apple sequoia
Apple sonoma

Tue, 29 Jul 2025 23:45:00 +0000

Type Values Removed Values Added
Description A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. Account-driven User Enrollment may still be possible with Lockdown Mode turned on.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:08:50.966Z

Reserved: 2025-04-16T15:24:37.087Z

Link: CVE-2025-43192

cve-icon Vulnrichment

Updated: 2025-07-30T13:31:33.853Z

cve-icon NVD

Status : Modified

Published: 2025-07-30T00:15:32.050

Modified: 2025-11-03T20:18:50.437

Link: CVE-2025-43192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T11:15:26Z

Weaknesses