CVE-2025-43231: Buffer Overflow
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8. An app may be able to access user-sensitive data.
Other sources
AMD. A buffer overflow was addressed with improved bounds checking.
— Apple
AppKit. The issue was resolved by blocking unsigned services from launching on Intel Macs.
— Apple
Apple Online Store Kit. A permissions issue was addressed with additional restrictions.
— Apple
AppSandbox. A permissions issue was addressed with additional restrictions.
— Apple
Call History. This issue was addressed with improved redaction of sensitive information.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43312
- CVE-2025-43321
- CVE-2025-31268
- CVE-2025-43285
- CVE-2025-43357
- CVE-2025-43349
- CVE-2025-43277
- CVE-2025-43273
- CVE-2025-43305
- CVE-2025-43290
- CVE-2025-43289
- CVE-2025-31271
- CVE-2025-43326
- CVE-2025-43302
- CVE-2025-31255
- CVE-2025-43359
- CVE-2025-43345
- CVE-2025-43231
- CVE-2025-43299
- CVE-2025-43295
- CVE-2025-43353
- CVE-2025-43319
- CVE-2025-43315
- CVE-2025-43355
- CVE-2025-43364
- CVE-2025-43301
- CVE-2025-43298
- CVE-2025-40909
- CVE-2025-43508
- CVE-2025-31269
- CVE-2024-27280
- CVE-2025-31259
- CVE-2025-43332
- CVE-2025-43293
- CVE-2025-43291
- CVE-2025-43286
- CVE-2025-43358
- CVE-2025-43367
- CVE-2025-43190
- CVE-2025-24197
- CVE-2025-43341
- CVE-2025-43314
- CVE-2025-43304
- CVE-2025-43306
- CVE-2025-43311
- CVE-2025-43308
- CVE-2025-43310
Frequently Asked Questions
What is the severity of CVE-2025-43231?
CVE-2025-43231 is considered a critical vulnerability due to its potential to allow unauthorized access to user-sensitive data.
How do I fix CVE-2025-43231?
To fix CVE-2025-43231, users should update to macOS Sonoma version 14.8 or later as this version includes the necessary patches.
What type of vulnerability is CVE-2025-43231?
CVE-2025-43231 is a logic issue that was addressed with improved checks and also involved a buffer overflow addressed with better bounds checking.
What systems are affected by CVE-2025-43231?
CVE-2025-43231 affects Apple macOS Sonoma up to version 14.7, where improved security measures are implemented in version 14.8.
Is it safe to use applications on affected systems for CVE-2025-43231?
Using applications on affected systems may pose risks until the update to macOS Sonoma 14.8 is applied to mitigate the vulnerability.