CVE-2025-43241: Race Condition
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to read files outside of its sandbox.
Other sources
Admin Framework. A path handling issue was addressed with improved validation.
— Apple
afclip. The issue was addressed with improved memory handling.
— Apple
AMD. A race condition was addressed with improved state handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue was addressed with additional code-signing restrictions.
— Apple
AppleMobileFileIntegrity. A logic issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43191
- CVE-2025-43186
- CVE-2025-43244
- CVE-2025-31243
- CVE-2025-43253
- CVE-2025-43249
- CVE-2025-43248
- CVE-2025-43245
- CVE-2025-43222
- CVE-2025-43223
- CVE-2025-43220
- CVE-2025-43210
- CVE-2025-43199
- CVE-2025-43195
- CVE-2025-43313
- CVE-2025-43187
- CVE-2025-43198
- CVE-2025-43254
- CVE-2025-43261
- CVE-2025-31279
- CVE-2025-24119
- CVE-2025-43255
- CVE-2025-43284
- CVE-2025-43209
- CVE-2025-43226
- CVE-2025-43282
- CVE-2025-43196
- CVE-2025-7424
- CVE-2025-43192
- CVE-2025-43275
- CVE-2025-43270
- CVE-2025-43225
- CVE-2025-43266
- CVE-2025-43260
- CVE-2025-43247
- CVE-2025-43194
- CVE-2025-43232
- CVE-2025-43236
- CVE-2025-43241
- CVE-2025-43233
- CVE-2025-43193
- CVE-2025-43250
- CVE-2025-43184
- CVE-2025-43197
- CVE-2025-43239
- CVE-2025-43243
- CVE-2025-43246
- CVE-2025-43256
- CVE-2025-43206
- CVE-2025-43189
- CVE-2025-43259
- CVE-2025-43238
- CVE-2025-24224
- CVE-2025-43281
- CVE-2025-43257
- CVE-2025-43277
- CVE-2025-43273
- CVE-2025-43230
- CVE-2025-43267
- CVE-2025-43188
- CVE-2025-43276
- CVE-2025-43268
- CVE-2025-43202
- CVE-2025-7425
- CVE-2025-31275
- CVE-2025-43234
- CVE-2025-43264
- CVE-2025-43219
- CVE-2025-31281
- CVE-2025-43224
- CVE-2025-43221
- CVE-2025-31280
- CVE-2025-43218
- CVE-2025-43215
- CVE-2025-43235
- CVE-2025-43274
- CVE-2025-24188
- CVE-2025-6965
- CVE-2025-43251
- CVE-2025-43185
- CVE-2025-43237
- CVE-2025-43229
- CVE-2025-43227
- CVE-2025-31278
- CVE-2025-31277
- CVE-2025-31273
- CVE-2025-43240
- CVE-2025-43214
- CVE-2025-43213
- CVE-2025-43212
- CVE-2025-43211
- CVE-2025-43265
- CVE-2025-43216
- CVE-2025-6558
- CVE-2025-43252
Frequently Asked Questions
What is the severity of CVE-2025-43241?
CVE-2025-43241 is classified as a moderate severity vulnerability due to the potential for unauthorized access to files outside of an app's sandbox.
How do I fix CVE-2025-43241?
To fix CVE-2025-43241, update your macOS to the latest versions: macOS Sequoia 15.6, macOS Sonoma 14.7.7, or macOS Ventura 13.7.7.
What versions of macOS are affected by CVE-2025-43241?
CVE-2025-43241 affects macOS Ventura versions prior to 13.7.7, macOS Sonoma versions prior to 14.7.7, and macOS Sequoia versions prior to 15.6.
Is CVE-2025-43241 a local or remote vulnerability?
CVE-2025-43241 is a local vulnerability that allows apps to potentially exploit permissions to access files outside their designated sandbox.
What are the risks associated with CVE-2025-43241?
The risks associated with CVE-2025-43241 include unauthorized data access, which can lead to data breaches and privacy violations.