Description
The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate their privileges.
Published: 2025-10-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation through authentication flaw
Action: Patch update
AI Analysis

Impact

A flaw in the authentication mechanism of macOS allows a local attacker to gain elevated privileges on the affected system. The weakness corresponds to CWE‑287, indicating that the authentication process can be bypassed or compromised, potentially giving the attacker full control of the machine. This flaw can be exploited when the attacker has local access, such as physical presence or an active local session, and can therefore use the elevated privileges to manipulate system settings, access sensitive data, or install malicious software.

Affected Systems

Apple macOS systems, particularly those running releases before Sequoia 15.6, are vulnerable. Apple explicitly states that the issue is corrected in macOS Sequoia 15.6. Any macOS version older than that that has not received this update remains at risk.

Risk and Exploitability

The CVSS score of 7.8 reflects a high severity for local privilege escalation. The EPSS score of less than 1% suggests that the exploitation probability is very low at this time, and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. The likely attack vector is local, requiring an attacker to be present on the target machine or otherwise have local code execution capability. Once exploited, the attacker can elevate privileges, potentially compromising the entire system’s integrity and confidentiality.

Generated by OpenCVE AI on April 27, 2026 at 23:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to macOS Sequoia 15.6 or any newer release to apply the authentication fix
  • Use device hardening practices such as enforcing strong password policies, enabling account lockouts after multiple failures, and disabling unnecessary login methods
  • Restrict physical and local access to systems by employing security controls such as secure boot, tamper‑evident enclosures, and remote management policies to reduce the chance of local privilege escalation

Generated by OpenCVE AI on April 27, 2026 at 23:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 26 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 21 Oct 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple macos Sequoia
Vendors & Products Apple macos Sequoia

Thu, 16 Oct 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Thu, 16 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate their privileges.
References

Subscriptions

Apple Macos Macos Sequoia
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:09:18.165Z

Reserved: 2025-04-16T15:24:37.101Z

Link: CVE-2025-43281

cve-icon Vulnrichment

Updated: 2025-10-16T14:39:15.701Z

cve-icon NVD

Status : Modified

Published: 2025-10-15T20:15:35.033

Modified: 2026-02-26T18:22:23.047

Link: CVE-2025-43281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T23:45:15Z

Weaknesses