Description
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.
Published: 2025-10-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to sensitive user data
Action: Patch immediately
AI Analysis

Impact

A logic flaw involving restricted access controls has been identified in macOS. The issue allows a local application to gain read access to content and other sensitive data it should not ordinarily see. The vulnerability stems from a flaw in how the system enforces user‑level permissions, enabling an application to bypass those checks and obtain confidential information.

Affected Systems

Apple macOS systems running versions prior to macOS Sequoia 15.6, macOS Sonoma 14.7.7, or macOS Ventura 13.7.7 are affected. The fix was delivered in those releases; any earlier macOS build remains vulnerable.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, and the EPSS score is below 1%, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring the attacker to run a malicious or compromised application on the target system. Given the weakness in access control (CWE‑284), exploitation would result in privileged read access to personal data rather than remote code execution or denial of service.

Generated by OpenCVE AI on April 27, 2026 at 23:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the operating system to macOS Sequoia 15.6, macOS Sonoma 14.7.7, or macOS Ventura 13.7.7 to apply the vendor fix.
  • Revoke or limit application permissions that access sensitive data via System Settings ► Privacy & Security.
  • Monitor system logs for unauthorized read attempts and consider enabling Gatekeeper or App Notarization controls for additional protection.

Generated by OpenCVE AI on April 27, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Title Logic flaw enables unauthorized access to sensitive user data in macOS

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13.7.7, macOS Sonoma 14.7.7, macOS Sequoia 15.6. An app may be able to access sensitive user data. A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.

Mon, 20 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple macos Sequoia
Apple macos Sonoma
Apple macos Ventura
Vendors & Products Apple macos Sequoia
Apple macos Sonoma
Apple macos Ventura

Thu, 16 Oct 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Wed, 15 Oct 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13.7.7, macOS Sonoma 14.7.7, macOS Sequoia 15.6. An app may be able to access sensitive user data.
References

Subscriptions

Apple Macos Macos Sequoia Macos Sonoma Macos Ventura
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:24:29.140Z

Reserved: 2025-04-16T15:24:37.106Z

Link: CVE-2025-43313

cve-icon Vulnrichment

Updated: 2025-10-15T20:41:18.933Z

cve-icon NVD

Status : Modified

Published: 2025-10-15T20:15:35.290

Modified: 2026-04-02T19:20:24.423

Link: CVE-2025-43313

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T23:45:15Z

Weaknesses