Description
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
Published: 2025-11-04
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to sensitive user data
Action: Patch Update
AI Analysis

Impact

A race condition in macOS may permit an application to read user data that should otherwise be inaccessible. The flaw originates from state handling that fails to serialize concurrent operations correctly, allowing sensitive data to be accessed via a timing exploit. Attackers could obtain personal or confidential information if the condition is triggered.

Affected Systems

Apple macOS versions prior to Sequoia 15.7.2, Sonoma 14.8.2, and Tahoe 26.1 are affected. All earlier releases in these macOS families remain vulnerable, while updated releases implement improved state handling that resolves the race condition.

Risk and Exploitability

The CVSS score of 4.7 indicates a moderate severity, and the EPSS score of <1% suggests a very low likelihood of real‑world exploitation. The flaw is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is local, requiring an application with elevated privileges or a user‑injected timing attack to trigger the race condition.

Generated by OpenCVE AI on April 28, 2026 at 22:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Sequoia 15.7.2, Sonoma 14.8.2, or Tahoe 26.1 to eliminate the race condition.
  • Enforce Gatekeeper hardening policies and restrict privileged third‑party applications to reduce the chance of exploiting the flaw.
  • Configure audit controls to detect abnormal privileged process execution or data read attempts, and apply any subsequent patches promptly.

Generated by OpenCVE AI on April 28, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 23:00:00 +0000

Type Values Removed Values Added
Title Race Condition Allowing Unauthorized Access to Sensitive User Data in macOS

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1, macOS Sonoma 14.8.2. An app may be able to access sensitive user data. A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

Wed, 17 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with improved state handling. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app may be able to access sensitive user data. A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1, macOS Sonoma 14.8.2. An app may be able to access sensitive user data.
References

Wed, 05 Nov 2025 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 04 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Apple macos Sequoia
Apple macos Sonoma
Vendors & Products Apple
Apple macos
Apple macos Sequoia
Apple macos Sonoma

Tue, 04 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with improved state handling. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app may be able to access sensitive user data.
References

Subscriptions

Apple Macos Macos Sequoia Macos Sonoma
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:20:14.374Z

Reserved: 2025-04-16T15:24:37.123Z

Link: CVE-2025-43420

cve-icon Vulnrichment

Updated: 2025-11-04T14:33:24.810Z

cve-icon NVD

Status : Modified

Published: 2025-11-04T02:15:47.883

Modified: 2026-04-02T19:20:43.610

Link: CVE-2025-43420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T22:45:25Z

Weaknesses