CVE-2025-43266: Race Condition
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.
Other sources
Admin Framework. A path handling issue was addressed with improved validation.
— Apple
afclip. The issue was addressed with improved memory handling.
— Apple
AMD. A race condition was addressed with improved state handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue was addressed with additional code-signing restrictions.
— Apple
AppleMobileFileIntegrity. A logic issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43191
- CVE-2025-43186
- CVE-2025-43244
- CVE-2025-31243
- CVE-2025-43253
- CVE-2025-43249
- CVE-2025-43248
- CVE-2025-43245
- CVE-2025-43222
- CVE-2025-43223
- CVE-2025-43220
- CVE-2025-43210
- CVE-2025-43199
- CVE-2025-43195
- CVE-2025-43313
- CVE-2025-43187
- CVE-2025-43198
- CVE-2025-43254
- CVE-2025-43261
- CVE-2025-31279
- CVE-2025-24119
- CVE-2025-43255
- CVE-2025-43284
- CVE-2025-43209
- CVE-2025-43226
- CVE-2025-43282
- CVE-2025-43196
- CVE-2025-7424
- CVE-2025-43192
- CVE-2025-43275
- CVE-2025-43270
- CVE-2025-43225
- CVE-2025-43266
- CVE-2025-43260
- CVE-2025-43247
- CVE-2025-43194
- CVE-2025-43232
- CVE-2025-43236
- CVE-2025-43241
- CVE-2025-43233
- CVE-2025-43193
- CVE-2025-43250
- CVE-2025-43184
- CVE-2025-43197
- CVE-2025-43239
- CVE-2025-43243
- CVE-2025-43246
- CVE-2025-43256
- CVE-2025-43206
- CVE-2025-43189
- CVE-2025-43259
- CVE-2025-43238
- CVE-2025-24224
- CVE-2025-43281
- CVE-2025-43257
- CVE-2025-43277
- CVE-2025-43273
- CVE-2025-43230
- CVE-2025-43267
- CVE-2025-43188
- CVE-2025-43276
- CVE-2025-43268
- CVE-2025-43202
- CVE-2025-7425
- CVE-2025-31275
- CVE-2025-43234
- CVE-2025-43264
- CVE-2025-43219
- CVE-2025-31281
- CVE-2025-43224
- CVE-2025-43221
- CVE-2025-31280
- CVE-2025-43218
- CVE-2025-43215
- CVE-2025-43235
- CVE-2025-43274
- CVE-2025-24188
- CVE-2025-6965
- CVE-2025-43251
- CVE-2025-43185
- CVE-2025-43237
- CVE-2025-43229
- CVE-2025-43227
- CVE-2025-31278
- CVE-2025-31277
- CVE-2025-31273
- CVE-2025-43240
- CVE-2025-43214
- CVE-2025-43213
- CVE-2025-43212
- CVE-2025-43211
- CVE-2025-43265
- CVE-2025-43216
- CVE-2025-6558
- CVE-2025-43252
Frequently Asked Questions
What is the severity of CVE-2025-43266?
CVE-2025-43266 has been classified with a severity rating that emphasizes its potential risk due to a permissions issue allowing apps to escape their sandbox.
How do I fix CVE-2025-43266?
To fix CVE-2025-43266, update affected systems to macOS Sequoia 15.6, macOS Sonoma 14.7.7, or macOS Ventura 13.7.7.
Which products are affected by CVE-2025-43266?
CVE-2025-43266 affects Apple macOS Ventura up to version 13.7.7, macOS Sonoma up to version 14.7.7, and macOS Sequoia up to version 15.6.
What type of vulnerability is CVE-2025-43266?
CVE-2025-43266 is a permissions issue that was resolved with additional restrictions to prevent sandbox escape.
Was CVE-2025-43266 previously exploited?
There are no confirmed reports of CVE-2025-43266 being actively exploited in the wild, but the nature of the vulnerability poses a significant risk.