Description
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.
Published: 2025-11-04
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential data disclosure through a downgrade attack
Action: Update OS
AI Analysis

Impact

A downgrade vulnerability that targets Intel‑based Macs allows a malicious or compromised application to bypass recent code‑signing restrictions added by Apple. By exploiting the flaw, the application can read user‑sensitive data that should otherwise be protected. The weakness is identified as CWE‑347, a downgrade flaw typical of improper validation of system components or certificates.

Affected Systems

The issue affects macOS running on Intel processors. The flaw is fixed in macOS Sequoia 15.7.2 and macOS Tahoe 26.1. All Intel‑based Mac systems that have not installed these updates, or any earlier release, remain potentially vulnerable; newer Apple silicon Macs are not affected.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. EPSS is reported at less than 1 %, implying a low risk of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local execution by a malicious or compromised app on an Intel Mac; once the downgrade exploit succeeds, an attacker can gain unauthorized read access to protected data.

Generated by OpenCVE AI on April 28, 2026 at 10:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to Sequoia 15.7.2 or Tahoe 26.1 to apply the code‑signing fix
  • Remove or disable legacy unsigned or unsigned applications that may trigger downgrade conditions
  • Verify that all third‑party applications are signed by trusted developers before installation

Generated by OpenCVE AI on April 28, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 10:45:00 +0000

Type Values Removed Values Added
Title Downgrade Vulnerability Enabling Local Data Disclosure on Intel Macs

Wed, 17 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
Description A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.2. An app may be able to access user-sensitive data. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.
References

Tue, 04 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple macos Sequoia
Vendors & Products Apple macos Sequoia

Tue, 04 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 04 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-347
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
Description A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.2. An app may be able to access user-sensitive data.
References

Subscriptions

Apple Macos Macos Sequoia
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:26:16.739Z

Reserved: 2025-04-16T15:24:37.117Z

Link: CVE-2025-43390

cve-icon Vulnrichment

Updated: 2025-11-04T14:39:46.184Z

cve-icon NVD

Status : Modified

Published: 2025-11-04T02:15:45.890

Modified: 2025-12-17T21:15:57.860

Link: CVE-2025-43390

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T10:30:29Z

Weaknesses