CVE-2025-43325: Buffer Overflow
Accounts. A parsing issue in the handling of directory paths was addressed with improved path validation.
Other sources
afpfs. A buffer overflow was addressed with improved bounds checking.
— Apple
AirPort. A permissions issue was addressed with additional restrictions.
— Apple
AMD. A buffer overflow was addressed with improved bounds checking.
— Apple
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.
— NVD
apache. This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.7.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.8.8
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43288
- CVE-2025-43208
- CVE-2025-43312
- CVE-2025-43321
- CVE-2025-43344
- CVE-2025-31268
- CVE-2025-43331
- CVE-2025-43317
- CVE-2025-43340
- CVE-2025-43337
- CVE-2025-43320
- CVE-2025-43285
- CVE-2025-43330
- CVE-2025-43346
- CVE-2025-43361
- CVE-2025-43451
- CVE-2025-43307
- CVE-2025-43354
- CVE-2025-43303
- CVE-2025-43357
- CVE-2025-43323
- CVE-2025-43403
- CVE-2025-43349
- CVE-2025-43292
- CVE-2025-43372
- CVE-2025-24088
- CVE-2025-43305
- CVE-2025-43290
- CVE-2025-43289
- CVE-2025-46284
- CVE-2025-43316
- CVE-2025-31271
- CVE-2025-31270
- CVE-2025-43326
- CVE-2025-43283
- CVE-2025-46280
- CVE-2025-43325
- CVE-2025-43287
- CVE-2025-43338
- CVE-2025-43302
- CVE-2025-31255
- CVE-2025-43366
- CVE-2025-43359
- CVE-2025-43345
- CVE-2025-43299
- CVE-2025-43295
- CVE-2025-43353
- CVE-2025-43294
- CVE-2025-43319
- CVE-2025-43315
- CVE-2025-43355
- CVE-2025-43207
- CVE-2025-43279
- CVE-2025-43301
- CVE-2025-43298
- CVE-2025-46310
- CVE-2025-40909
- CVE-2025-43297
- CVE-2025-31269
- CVE-2025-43204
- CVE-2024-27280
- CVE-2025-46306
- CVE-2025-43327
- CVE-2025-43329
- CVE-2025-43328
- CVE-2025-43318
- CVE-2025-46307
- CVE-2025-31259
- CVE-2025-43332
- CVE-2025-43293
- CVE-2025-43291
- CVE-2025-43286
- CVE-2025-43369
- CVE-2025-43358
- CVE-2025-43367
- CVE-2025-43190
- CVE-2025-43333
- CVE-2025-24197
- CVE-2025-6965
- CVE-2025-43341
- CVE-2025-43314
- CVE-2025-43304
- CVE-2025-43306
- CVE-2025-43347
- CVE-2025-43296
- CVE-2025-43311
- CVE-2025-43308
- CVE-2025-43262
- CVE-2025-43356
- CVE-2025-43272
- CVE-2025-43343
- CVE-2025-43342
- CVE-2025-43419
- CVE-2025-43376
- CVE-2025-43368
- CVE-2025-43310
- CVE-2026-43749
- CVE-2026-64767
- CVE-2026-23918
- CVE-2026-64695
- CVE-2026-43801
- CVE-2026-43781
- CVE-2026-64737
- CVE-2026-43748
- CVE-2026-43776
- CVE-2026-43681
- CVE-2026-43672
- CVE-2026-43763
- CVE-2026-64702
- CVE-2026-64725
- CVE-2026-64747
- CVE-2026-64762
- CVE-2026-64707
- CVE-2026-28849
- CVE-2026-64698
- CVE-2026-64734
- CVE-2026-43756
- CVE-2026-43693
- CVE-2026-43673
- CVE-2026-43744
- CVE-2026-43803
- CVE-2026-43775
- CVE-2026-43711
- CVE-2026-28936
- CVE-2026-43738
- CVE-2026-43802
- CVE-2026-64710
- CVE-2026-39875
- CVE-2026-43698
- CVE-2026-3784
- CVE-2026-3783
- CVE-2026-43758
- CVE-2026-64708
- CVE-2026-28926
- CVE-2026-43747
- CVE-2026-64694
- CVE-2026-28945
- CVE-2026-64776
- CVE-2026-43793
- CVE-2026-43753
- CVE-2026-43714
- CVE-2026-64740
- CVE-2026-43796
- CVE-2026-64692
- CVE-2026-43682
- CVE-2026-28981
- CVE-2026-43773
- CVE-2026-43767
- CVE-2026-64697
- CVE-2026-43764
- CVE-2026-43710
- CVE-2026-64716
- CVE-2026-43780
- CVE-2026-43818
- CVE-2026-43661
- CVE-2026-64754
- CVE-2026-64693
- CVE-2026-43805
- CVE-2026-39877
- CVE-2026-64749
- CVE-2026-43782
- CVE-2026-64744
- CVE-2026-64775
- CVE-2026-28982
- CVE-2026-43778
- CVE-2026-64735
- CVE-2026-43822
- CVE-2026-64700
- CVE-2026-43799
- CVE-2026-43810
- CVE-2026-43724
- CVE-2026-43722
- CVE-2026-43809
- CVE-2026-43757
- CVE-2026-43769
- CVE-2026-43754
- CVE-2026-64723
- CVE-2026-39868
- CVE-2026-64709
- CVE-2026-64721
- CVE-2026-20672
- CVE-2026-28983
- CVE-2026-4424
- CVE-2026-28900
- CVE-2026-28973
- CVE-2026-64739
- CVE-2026-43703
- CVE-2026-43706
- CVE-2026-43766
- CVE-2026-64738
- CVE-2026-43653
- CVE-2026-64724
- CVE-2026-43723
- CVE-2026-43807
- CVE-2026-43733
- CVE-2026-43729
- CVE-2026-64772
- CVE-2026-64774
- CVE-2026-64770
- CVE-2026-64769
- CVE-2026-64722
- CVE-2026-64768
- CVE-2026-64771
- CVE-2026-43771
- CVE-2026-43772
- CVE-2026-28961
- CVE-2026-64711
- CVE-2026-28912
- CVE-2026-43765
- CVE-2026-28896
- CVE-2026-64731
- CVE-2026-43812
- CVE-2026-43694
- CVE-2026-39874
- CVE-2026-64764
- CVE-2026-64763
- CVE-2026-64766
- CVE-2026-64765
- CVE-2026-43779
- CVE-2026-43777
- CVE-2026-43665
- CVE-2026-64745
- CVE-2026-39873
- CVE-2026-64696
- CVE-2026-64704
- CVE-2026-43774
- CVE-2026-43770
- CVE-2026-43768
- CVE-2026-64703
- CVE-2026-64699
- CVE-2026-43750
- CVE-2026-28932
- CVE-2026-28914
- CVE-2026-28911
- CVE-2026-43760
- CVE-2026-43755
Frequently Asked Questions
What is the severity of CVE-2025-43325?
CVE-2025-43325 is considered a high severity vulnerability due to potential unauthorized access to sensitive user data.
How do I fix CVE-2025-43325?
To fix CVE-2025-43325, update your macOS Tahoe to version 26 or later as this version contains the necessary security enhancements.
What types of issues does CVE-2025-43325 address?
CVE-2025-43325 addresses permissions issues, buffer overflow vulnerabilities, and access issues through improved bounds and sandbox restrictions.
What can be compromised due to CVE-2025-43325?
CVE-2025-43325 may allow applications to access sensitive user data without proper authorization.
Which versions of macOS are affected by CVE-2025-43325?
CVE-2025-43325 affects all versions of Apple macOS Tahoe prior to version 26.