CVE-2025-43288
Published Sep 15, 2025
·Updated
AppleMobileFileIntegrity. The issue was addressed by adding additional logic.
Credit
Rodolphe BRUNETTI@@eisw0lf(Lupus Nova), ABC Research s.r.o., Mickey Jin@@patch1t, Csaba Fitzl@@theevilbit(Kandji), Nolan Astrein(Kandji), Zhongquan Li@@Guluisacat, Bilal Siddiqui, @@zlluny(Trend Zero Day Initiative), an anonymous researcher, Wang Yu(Cyberserval), Keisuke Hosoda, Viktor Oreshkin, Nathaniel Oh@@calysteon, Hikerell (Loadshine Lab), Rodolphe Brunetti@@eisw0lf(Lupus Nova), Dawuge(Shuffle Team), LFY@@secsys(Fudan University), CVE-2025-40909, CVE-2024-27280, Ye Zhang(Baidu Security), pattern-f@@pattern_F_, @@zlluny, 정답이 아닌 해답, Noah Gregory (wts.dev), Justin Elliot Fu, Kirin@@Pwnrin, Mickey Jin@@patch1t(Cisco Talos), Kirin@@Pwnrin(Cisco Talos), Claudio Bozzato(Cisco Talos), Francesco Benvenuto(Cisco Talos), Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Michael Reeves@@IntegralPilot, Rosyna Keller(Totally Not Malicious Software), Guilherme Rambo(Best Buddy Apps), Yinyi Wu@@_3ndy1(Dawn Security Lab of JD), @@zlluny(Trend Micro Zero Day Initiative), 이동하 (Lee Dong Ha)(SSA Lab), Shantanu Thakur, Anonymous(Trend Micro Zero Day Initiative), Yiğit Can YILMAZ@@yilmazcanyigit, Ye Zhang@@VAR10CK(Baidu Security), Gergely Kalman@@gergely_kalman, Zhongcheng Li(IES Red Team of ByteDance), KPC(Cisco Talos), @@RenwaX23, Kirin@@Pwnrin(Computer Science), Cristian Dinca(Computer Science), Romania, CVE-2025-6965, JZ, Seo Hyun-gyu@@wh1te4ever, Luke Roberts@@rookuu, Ferdous Saljooki@@malwarezoo(Jamf), Pyrophoria(GrapheneOS), an anonymous researcher(GrapheneOS), James J Kalafus, Michel Migdal, ken super, Jaydev Ahire, Big Bear, Ignacio Sanmillan@@ulexec, Mike Cardwell(grepular), Bob Lord, Pawel Wylecial(REDTEAM)
Affected Software
4 affected componentsFixes available
Apple macOS Sequoia<15.7
Apple macOS<15.7
Apple macOS Sequoia<15.7
15.7
Apple macOS Tahoe<26
26
Event History
Sep 15, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Nov 4, 2025
CVE Published
via MITRE·01:17 AM
Data Sourced
via MITRE·01:17 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43288?
The severity of CVE-2025-43288 is classified as high due to the potential for apps to bypass Privacy preferences.
2
How do I fix CVE-2025-43288?
To fix CVE-2025-43288, update to macOS Sequoia version 15.7 or later.
3
Which versions of macOS are affected by CVE-2025-43288?
macOS Sequoia versions prior to 15.7 are affected by CVE-2025-43288.
4
What type of issue is CVE-2025-43288?
CVE-2025-43288 involves a validation issue related to symlinks that can affect privacy settings.
5
Can CVE-2025-43288 affect app security?
Yes, CVE-2025-43288 can potentially allow malicious apps to bypass important Privacy preferences, impacting user security.