5.5
CVE-2025-43326 - Out-of-Bounds Read Causing Sensitive Data Exposure in macOS
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access sensitive user data.
7.1
CVE-2025-43263 - Xcode Sandbox Bypass Grants Unauthorized File Access
The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox.
8.2
CVE-2025-43371 - Potential Sandbox Escape in Apple Xcode via Improper Privilege Control
This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox.
9.8
CVE-2025-31255 - Authorization Flaw in Apple iOS and macOS Allowing Sensitive Data Access
An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, watchOS 26. An app may be able to access sensitive user data.
9.8
CVE-2025-43347 - Input Validation Vulnerability in Apple Operating Systems
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An input validation issue was addressed.
4.4
CVE-2025-43310 - Pasteboard Sensitive Data Exposure via User Tricking
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to trick a user into copying sensitive data to the pasteboard.
6.2
CVE-2025-43279 - App May Access User-Sensitive Data Through Improper Log Entry Redaction
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26. An app may be able to access user-sensitive data.
6.5
CVE-2025-30468 - Unauthorized Access to Private Browsing Tabs via Improper State Management
This issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsing tabs may be accessed without authentication.
6.2
CVE-2025-43297 - Type Confusion Causing Denial of Service on macOS Tahoeβ―26
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26. An app may be able to cause a denial-of-service.
5.1
CVE-2025-43311 - Unauthorized Access to Protected User Data via Missing Entitlement Checks
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access protected user data.