Security Vulnerability Report
中文
CVE-2025-43471 CVSS 5.5 MEDIUM

CVE-2025-43471

Published: 2025-12-12 21:15:55
Last Modified: 2025-12-16 22:15:47

Description

The issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

CVSS Details

CVSS Score
5.5
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Configurations (Affected Products)

cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* - VULNERABLE
macOS Tahoe 26.1 (所有受影响版本)
macOS Tahoe < 26.1

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
# CVE-2025-43471 PoC - macOS Tahoe 26.1 Permission Bypass # Note: This PoC is for educational and research purposes only # Requires local code execution as low-privilege user import Foundation import Security class CVE202543471Exploit { func checkVulnerability() -> Bool { // Attempt to access protected user data resources // This simulates the vulnerability exploitation let sensitivePaths = [ "~/Library/Application Support/", "~/Library/Preferences/", "~/Library/Accounts/", "~/Library/Personalization/", "/Users/Shared/", ] for path in sensitivePaths { let expandedPath = (path as NSString).expandingTildeInPath let fileManager = FileManager.default // Try to enumerate contents without proper privileges do { let contents = try fileManager.contentsOfDirectory(atPath: expandedPath) // If we can read protected directories without elevation print("Potentially vulnerable: Able to read \(path)") return true } catch { print("Access denied for \(path)") } } return false } func exploit() { // Exploitation attempt print("CVE-2025-43471 Exploitation Attempt") print("Target: macOS Tahoe 26.1") print("Vulnerability: Permission bypass leading to sensitive data access") if checkVulnerability() { print("[!] System may be vulnerable to CVE-2025-43471") print("[!] Sensitive user data may be accessible without proper privileges") } else { print("[+] System appears patched or not vulnerable") } } } // Execute vulnerability check let exploit = CVE202543471Exploit() exploit.exploit()

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-43471", "sourceIdentifier": "[email protected]", "published": "2025-12-12T21:15:55.090", "lastModified": "2025-12-16T22:15:47.180", "vulnStatus": "Modified", "cveTags": [], "descriptions": [{"lang": "en", "value": "The issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE"}, "exploitabilityScore": 1.8, "impactScore": 3.6}, {"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE"}, "exploitabilityScore": 1.8, "impactScore": 3.6}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}, {"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-497"}]}], "configurations": [{"nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*", "versionEndExcluding": "26.1", "matchCriteriaId": "081B6CCE-FFA4-409C-9353-15014F3AF436"}]}]}], "references": [{"url": "https://support.apple.com/en-us/125634", "source": "[email protected]", "tags": ["Release Notes", "Vendor Advisory"]}]}}