7.8
CVE-2025-43204 - macOS Sandbox Escape Vulnerability
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to break out of its sandbox.
7.8
CVE-2025-43341 - macOS Root Privilege Escalation via Permission Flaw
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to gain root privileges.
7.8
CVE-2025-43316 - Malicious App Can Gain Root Privileges Through Permissions Flaw in macOS and visionOS
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26, visionOS 26. A malicious app may be able to gain root privileges.
5.5
CVE-2025-31269 -
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access protected user data.
7.8
CVE-2025-43286 - Permissions-based Sandbox Escape Vulnerability in macOS
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to break out of its sandbox.
5.5
CVE-2025-43208 - Permissions Vulnerability Permits Unauthorized Reading of Sensitive Location Data
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to read sensitive location information.
7.5
CVE-2025-24088 - App may override MDMβenforced profile settings on macOS
The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app may be able to override MDM-enforced settings from profiles.
5.5
CVE-2025-43321 - Unsigned Services on Intel Macs May Access Protected User Data
The issue was resolved by blocking unsigned services from launching on Intel Macs. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access protected user data.
5.5
CVE-2025-43337 - macOS Sandbox Access Control Issue Allowing Sensitive Data Access
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26. An app may be able to access sensitive user data.
6.5
CVE-2025-43272 - webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.