CVE-2025-43471
Published Nov 3, 2025
·Updated
Admin Framework. The issue was addressed with improved checks.
Credit
Gergely Kalman@@gergely_kalman, Ryan Dowd@@_rdowd, Ron Masas(BreakPoint), Pinak Oza, an anonymous researcher, Mickey Jin@@patch1t, Joseph Ravichandran@@0xjprx(MIT CSAIL), Dave G. (supernetworks.org), JZ, Zhongcheng Li(IES Red Team of ByteDance), Duy Trần@@khanhduytran0, Csaba Fitzl@@theevilbit(Kandji), Hikerell (Loadshine Lab), Wojciech Regula(SecuRing), Kirin@@Pwnrin(Fudan University), LFY@@secsys(Fudan University), 이동하 (Lee Dong Ha(BoB 14th), wac(Trend Micro Zero Day Initiative), Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Adwiteeya Agrawal, Kenneth Chew, Rodolphe BRUNETTI@@eisw0lf(Lupus Nova), @@EthanArbuckle, pattern-f@@pattern_F_, iisBuri, Ferdous Saljooki@@malwarezoo(Jamf), Murray Mike, Cristian Dinca (icmd.tech), Apple, Dave G.(supernetworks), Alex Radocea(supernetworks), Taavi Eomäe(Zone Media), Romain Lebesle(Khatima), Himanshu Bharti@@Xpl0itme(Khatima), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), BynarIO AI (bynar.io), Google Threat Analysis Group, Doug Hogan, Kirin@@Pwnrin, Asaf Cohen, KPC(Cisco Talos), CVE-2024-43398, CVE-2024-49761, CVE-2025-6442, @@RenwaX23, Zhongquan Li@@Guluisacat, Stanislav Jelezoglo, Vivek Dhar, ASI (RM) in Border Security Force, FTR HQ BSF Kashmir, Nikolai Skliarenko(Trend Micro Zero Day Initiative), an anonymous researcher(Microsoft), Kirin@@Pwnrin(Microsoft), Jonathan Bar Or@@yo_yo_yo_jbo(Microsoft), Amy@@asentientbot, CVE-2025-32462, CVE-2025-53906, Aleksejs Popovs, Phil Beauvoir, Google Big Sleep, Gary Kwong, rheza@@ginggilBesel, Justin Cohen(Google), Nan Wang@@eternalsakura13, rheza@@ginggilBesel(Trend Micro Zero Day Initiative), shandikri(Trend Micro Zero Day Initiative), Gary Kwong(Trend Micro Zero Day Initiative), Tom Van Goethem, Wang Yu(Cyberserval), @@cloudlldb, Morris Richman@@morrisinlife
Affected Software
2 affected componentsFixes available
Apple macOS Tahoe<26.1
26.1
Apple macOS<26.1
Event History
Nov 3, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Dec 12, 2025
CVE Published
via MITRE·08:57 PM
Data Sourced
via MITRE·08:57 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43471?
CVE-2025-43471 is considered a high severity vulnerability due to potential exploitation in Apple macOS Tahoe.
2
How do I fix CVE-2025-43471?
To fix CVE-2025-43471, upgrade to Apple macOS Tahoe version 26.1 or later.
3
Which versions of macOS Tahoe are affected by CVE-2025-43471?
CVE-2025-43471 affects all versions of Apple macOS Tahoe prior to version 26.1.
4
What type of vulnerability is CVE-2025-43471?
CVE-2025-43471 is an admin framework issue addressed with improved checks.
5
Is there any workaround for CVE-2025-43471?
There are no known workarounds for CVE-2025-43471, and upgrading is the recommended solution.