Description
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to modify protected parts of the file system.
Published: 2025-07-29
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a user‑level application to write to protected parts of the macOS file system, which constitutes a direct violation of access control checks (CWE-284). This capability could be used to modify system files or replace critical configuration data, thereby compromising the integrity of the operating system. The flaw is specifically about bypassing or weakening the safeguards that normally prevent non‑privileged processes from altering protected directories.

Affected Systems

Apple macOS installations before Sequoia 15.6, Sonoma 14.7.7, and Ventura 13.7.7 are affected. The issue exists on any macOS version that has not yet applied the updates listed in the advisory; all prior releases are vulnerable.

Risk and Exploitability

The CVSS score of 9.8 marks the flaw as critical. The EPSS score is reported as less than 1%, indicating that exploitation attempts are currently rare. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector involves a local or privileged application executing code that writes to protected file system locations; no evidence of a remote exploitation path is provided.

Generated by OpenCVE AI on April 28, 2026 at 18:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the macOS update that includes the security fix: Sequoia 15.6 or newer, Sonoma 14.7.7 or newer, or Ventura 13.7.7 or newer.
  • If an update cannot be applied immediately, enforce stricter application sandboxing and limit the installation of unsigned or untrusted applications to reduce the attack surface.
  • Verify that critical system directories retain write permissions for root and administrators only, removing any unintended group or world write access.

Generated by OpenCVE AI on April 28, 2026 at 18:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-23123 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to modify protected parts of the file system.
History

Tue, 28 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Title Application Can Modify Protected File System Parts in macOS

Mon, 03 Nov 2025 20:30:00 +0000


Thu, 31 Jul 2025 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 30 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Jul 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Apple macos Sequoia
Apple macos Sonoma
Apple macos Ventura
Vendors & Products Apple
Apple macos
Apple macos Sequoia
Apple macos Sonoma
Apple macos Ventura

Tue, 29 Jul 2025 23:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to modify protected parts of the file system.
References

Subscriptions

Apple Macos Macos Sequoia Macos Sonoma Macos Ventura
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:13:04.100Z

Reserved: 2025-04-16T15:24:37.087Z

Link: CVE-2025-43194

cve-icon Vulnrichment

Updated: 2025-11-03T19:59:43.031Z

cve-icon NVD

Status : Modified

Published: 2025-07-30T00:15:32.267

Modified: 2025-11-03T20:18:50.773

Link: CVE-2025-43194

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T19:00:20Z

Weaknesses