Description
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
Published: 2025-11-04
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure of sensitive user data
Action: Patch Now
AI Analysis

Impact

A permissions flaw in macOS sandbox restrictions can enable an application to access sensitive user data that it should not normally read. The vulnerability is classified as CWE‑359, indicating a failure to enforce proper isolation boundaries. If successfully exploited, an attacker could read files, credentials, or other private information stored on the device without getting user consent.

Affected Systems

Apple’s macOS operating system is affected. The flaw is fixed in macOS Sequoia 15.7.2 and macOS Tahoe 26.1; any release before those versions may remain vulnerable if not upgraded.

Risk and Exploitability

The CVSS score of 5.5 places the issue in the medium severity range, while an EPSS score of less than 1% indicates a low current likelihood of exploitation. The vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is the delivery of a malicious application that bypasses sandbox permission checks; local or remote installation of such an app is considered the most probable exploitation path, based on the description.

Generated by OpenCVE AI on April 28, 2026 at 10:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to Sequoia 15.7.2 or later, or macOS Tahoe 26.1 or later
  • Ensure all installed applications are signed by trusted developers and sourced from the Apple App Store
  • Configure security settings to enforce strict App Sandbox permissions and monitor file‑access logs for anomalous activity

Generated by OpenCVE AI on April 28, 2026 at 10:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 11:00:00 +0000

Type Values Removed Values Added
Title macOS Sandbox Permissions Flaw Enabling Unauthorized Data Access

Wed, 17 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2. An app may be able to access sensitive user data. A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
References

Wed, 05 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Tue, 04 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Nov 2025 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 04 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Tue, 04 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-359
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 04 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:08:06.038Z

Reserved: 2025-04-16T15:24:37.121Z

Link: CVE-2025-43409

cve-icon Vulnrichment

Updated: 2025-11-04T16:00:51.034Z

cve-icon NVD

Status : Modified

Published: 2025-11-04T02:15:47.307

Modified: 2025-12-17T21:15:59.770

Link: CVE-2025-43409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T10:45:29Z

Weaknesses