Description
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may be able to gain root privileges.
Published: 2025-12-12
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to Root
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a permissions issue that can allow a user‑level application to obtain root privileges, constituting a local privilege escalation. The weakness corresponds to CWE‑280, inadequate access control, and would enable an attacker who can execute code as a normal user to perform any operation the operating system permits, including installing software, modifying critical system files, and bypassing security controls.

Affected Systems

Apple macOS is affected, specifically versions of macOS Sequoia and macOS Tahoe that are older than Sequoia 15.7.3 and Tahoe 26.2. The security update that addresses the issue is available in those releases; earlier releases remain vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity risk. The EPSS score of less than 1% suggests that exploitation is unlikely at present, and the vulnerability is not listed in CISA's KEV catalog, indicating no known exploits. The attack vector is inferred to be local, as the flaw requires that a malicious application be run by a user—there are no network‑based remote triggers documented.

Generated by OpenCVE AI on April 22, 2026 at 20:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update macOS to Sequoia 15.7.3 or Tahoe 26.2.
  • If an update is not immediately possible, restrict or disable the installation and execution of non‑Apple‑signed applications to reduce the risk of privilege escalation.
  • Enable and regularly review system audit logs for unexpected root‑level activity to detect any exploitation attempts early.

Generated by OpenCVE AI on April 22, 2026 at 20:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 21:00:00 +0000

Type Values Removed Values Added
Title macOS Permissions Escalation Allowing Apps to Gain Root Privileges

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2, macOS Sequoia 15.7.3. An app may be able to gain root privileges. A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may be able to gain root privileges.

Wed, 17 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3. An app may be able to gain root privileges. A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2, macOS Sequoia 15.7.3. An app may be able to gain root privileges.
References

Mon, 15 Dec 2025 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Sun, 14 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Sat, 13 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-280
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 12 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3. An app may be able to gain root privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:14:22.444Z

Reserved: 2025-04-16T15:27:21.197Z

Link: CVE-2025-43527

cve-icon Vulnrichment

Updated: 2025-12-13T22:43:35.881Z

cve-icon NVD

Status : Modified

Published: 2025-12-12T21:15:57.207

Modified: 2026-04-02T19:20:59.877

Link: CVE-2025-43527

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T20:45:27Z

Weaknesses