5.5
CVE-2025-43215 - Image Processing Memory Disclosure in macOS
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may result in disclosure of process memory.
7.8
CVE-2025-43188 - Privilege Escalation via Permissions Issue in macOS Sequoia
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gain root privileges.
6.1
CVE-2025-8319 -
the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the pageโs Document Object Model via the error= URL parameter
9.8
CVE-2025-43261 - Sandbox Escape via Logic Flaw in macOS Enabling Privilege Escalation
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.
8.8
CVE-2025-31277 - webkitgtk: Processing maliciously crafted web content may lead to memory corruption
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
7.8
CVE-2025-43277 - Memory Corruption via Malicious Audio File
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, macOS Sonoma 14.8, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted audio file may lead to memory corruption.
9.8
CVE-2025-43220 - Symlink Validation Flaw Enables Unauthorized Access to Protected User Data
This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected user data.
5.5
CVE-2025-43241 -
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to read files outside of its sandbox.
6.2
CVE-2025-43240 - webkitgtk: A downloadโs origin may be incorrectly associated
A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated.
7.8
CVE-2025-43256 - Privilege Escalation via Improper State Management in macOS
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to gain root privileges.