4.7
CVE-2025-43420 - Race Condition Allowing Unauthorized Access to Sensitive User Data in macOS
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
5.5
CVE-2025-43498 - Authorization Bypass via State Management in Apple OS
An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1. An app may be able to access sensitive user data.
5.5
CVE-2025-43477 - Privacy Leak: Sensitive User Data Exposure via Log Redaction Failure
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
5.5
CVE-2025-43499 - Access Control Bypass Allowing Apps to Read Sensitive User Data on Apple Devices
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
7.8
CVE-2025-43476 - Sandbox Escape via Permission Misuse in macOS
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to break out of its sandbox.
4.3
CVE-2025-43421 - webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
4.6
CVE-2025-43460 - Logic flaw allowing physical access attacker to view sensitive data on locked iOS and iPadOS devices
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.
5.5
CVE-2025-43335 - macOS Access Control Bypass Allows Apps to Read Sensitive User Data
The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.
8.1
CVE-2025-43323 - Apple OS Fingerprinting Vulnerability via Missing Entitlement Check
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to fingerprint the user.
5.4
CVE-2025-43495 - Unauthorized Keylogging via App Without User Permission
The issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to monitor keystrokes without user permission.