Description
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.
Published: 2025-11-04
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to User Data
Action: Patch Now
AI Analysis

Impact

The vulnerability is a logic flaw that undermines existing checks for user‑sensitive data access. Because the flaw is not an injection or buffer overflow, it does not provide direct code execution. Instead, it allows a locally installed application to read or obtain data that should be protected, creating a privilege‑bypass of the operating system’s sandboxing controls. This type of weakness is classified as CWE‑284, reflecting a straight‑forward access‑control bypass that can compromise confidentiality of private files and system settings.

Affected Systems

The flaw affects Apple macOS operating systems released before the patches described in Apple support articles 125634–125636. The fixes are included in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, and macOS Tahoe 26.1. All earlier releases in those product lines are considered vulnerable until an update is applied.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity, but the derived EPSS score of less than 1% suggests that the likelihood of an exploit being used in the wild is currently very low. The vulnerability is not listed in the CISA KEV catalog. Attack vectors are inferred to be local, where a user‑installed application can exercise the logic flaw to read protected data. No high‑impact prerequisite conditions are mentioned, so exploiting the bug requires only the presence of a malicious or misbehaving application on the user’s machine.

Generated by OpenCVE AI on April 27, 2026 at 23:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update macOS to Sequoia 15.7.2, Sonoma 14.8.2, or Tahoe 26.1, which contain the vendor fix.
  • Avoid installing or running unsigned third‑party applications, as they are the most likely vectors for the logic flaw.
  • Maintain an automated patch‑management system to apply OS updates quickly, ensuring that the new version is reached before new exploits emerge.

Generated by OpenCVE AI on April 27, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 23:30:00 +0000

Type Values Removed Values Added
Title macOS Logic Error Enables Unauthorized App Access to User Data

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1, macOS Sonoma 14.8.2. An app may be able to access user-sensitive data. A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.

Wed, 17 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app may be able to access user-sensitive data. A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1, macOS Sonoma 14.8.2. An app may be able to access user-sensitive data.
References

Tue, 04 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 04 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Apple macos Sequoia
Apple macos Sonoma
Vendors & Products Apple
Apple macos
Apple macos Sequoia
Apple macos Sonoma

Tue, 04 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app may be able to access user-sensitive data.
References

Subscriptions

Apple Macos Macos Sequoia Macos Sonoma
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:20:55.648Z

Reserved: 2025-04-16T15:24:37.108Z

Link: CVE-2025-43322

cve-icon Vulnrichment

Updated: 2025-11-04T17:51:20.180Z

cve-icon NVD

Status : Modified

Published: 2025-11-04T02:15:39.250

Modified: 2026-04-02T19:20:25.950

Link: CVE-2025-43322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T23:15:06Z

Weaknesses