Description
The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.
Published: 2025-12-12
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via launch constraint bypass
Action: Apply Patch
AI Analysis

Impact

An application can bypass launch constraint protections and execute malicious code with elevated privileges, a classic privilege escalation flaw. The weakness is classified as CWE‑269: Improper Privilege Management. The vulnerability allows an attacker to run code with higher permissions than intended, potentially compromising data integrity and confidentiality for the affected system.

Affected Systems

Apple macOS systems are affected. The issue was fixed in macOS Sequoia 15.7.3 and macOS Tahoe 26, meaning earlier releases of these macOS versions are vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score is less than 1 %, showing a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The attack likely requires a local application that can manipulate launchd to enforce the bypass, as no remote trigger is indicated.

Generated by OpenCVE AI on April 27, 2026 at 22:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to macOS Sequoia 15.7.3 or macOS Tahoe 26 to apply the vendor fix.
  • Ensure System Integrity Protection is enabled to prevent unauthorized process execution.
  • Monitor system logs for anomalous launchd activity and investigate suspicious privilege‑gaining attempts.

Generated by OpenCVE AI on April 27, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 23:00:00 +0000

Type Values Removed Values Added
Title Privileged Code Execution via Launch Constraint Bypass in macOS

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26, macOS Sequoia 15.7.3. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges. The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.

Mon, 05 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 17 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
Description The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges. The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26, macOS Sequoia 15.7.3. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.
References

Tue, 16 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sun, 14 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Apple macos Sequoia
Vendors & Products Apple
Apple macos
Apple macos Sequoia

Fri, 12 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Description The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.
References

Subscriptions

Apple Macos Macos Sequoia
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:15:11.752Z

Reserved: 2025-04-16T15:24:37.108Z

Link: CVE-2025-43320

cve-icon Vulnrichment

Updated: 2026-01-05T17:20:32.604Z

cve-icon NVD

Status : Modified

Published: 2025-12-12T21:15:53.300

Modified: 2026-04-02T19:20:25.603

Link: CVE-2025-43320

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T22:45:15Z

Weaknesses