CVE-2025-43508: Use After Free
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
Other sources
Admin Framework. A logic issue was addressed with improved checks.
— Apple
Admin Framework. The issue was addressed with improved checks.
— Apple
AMD. A buffer overflow was addressed with improved bounds checking.
— Apple
App Store. A logging issue was addressed with improved data redaction.
— Apple
AppKit. The issue was resolved by blocking unsigned services from launching on Intel Macs.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43288
- CVE-2025-43312
- CVE-2025-43321
- CVE-2025-31268
- CVE-2025-43285
- CVE-2025-43330
- CVE-2025-43357
- CVE-2025-43349
- CVE-2025-43292
- CVE-2025-43305
- CVE-2025-43290
- CVE-2025-43289
- CVE-2025-46284
- CVE-2025-43464
- CVE-2025-31271
- CVE-2025-43326
- CVE-2025-43302
- CVE-2025-31255
- CVE-2025-43359
- CVE-2025-43345
- CVE-2025-43299
- CVE-2025-43295
- CVE-2025-43353
- CVE-2025-43319
- CVE-2025-43315
- CVE-2025-43355
- CVE-2025-43364
- CVE-2025-43301
- CVE-2025-43298
- CVE-2025-40909
- CVE-2025-43508
- CVE-2024-27280
- CVE-2025-31259
- CVE-2025-43332
- CVE-2025-43293
- CVE-2025-43291
- CVE-2025-43286
- CVE-2025-43358
- CVE-2025-43190
- CVE-2025-24197
- CVE-2025-43314
- CVE-2025-43304
- CVE-2025-43306
- CVE-2025-43311
- CVE-2025-43308
- CVE-2025-43310
- CVE-2025-43277
- CVE-2025-43273
- CVE-2025-43231
- CVE-2025-31269
- CVE-2025-43367
- CVE-2025-43341
- CVE-2025-43471
- CVE-2025-43322
- CVE-2025-46313
- CVE-2025-43455
- CVE-2025-43447
- CVE-2025-43462
- CVE-2025-43390
- CVE-2025-43388
- CVE-2025-43466
- CVE-2025-43382
- CVE-2025-43468
- CVE-2025-43379
- CVE-2025-43378
- CVE-2025-43478
- CVE-2025-43407
- CVE-2025-43446
- CVE-2025-43465
- CVE-2025-43423
- CVE-2025-43497
- CVE-2025-43394
- CVE-2025-43448
- CVE-2025-43395
- CVE-2025-43461
- CVE-2025-43426
- CVE-2025-43401
- CVE-2025-43479
- CVE-2025-43436
- CVE-2025-43381
- CVE-2025-43445
- CVE-2025-43481
- CVE-2025-43470
- CVE-2025-46315
- CVE-2025-43387
- CVE-2025-43420
- CVE-2025-43498
- CVE-2025-43507
- CVE-2025-43348
- CVE-2025-43474
- CVE-2025-43396
- CVE-2025-43444
- CVE-2025-43467
- CVE-2025-43398
- CVE-2025-43510
- CVE-2025-43520
- CVE-2025-43413
- CVE-2025-43494
- CVE-2025-43496
- CVE-2025-43386
- CVE-2025-43385
- CVE-2025-43384
- CVE-2025-43383
- CVE-2025-43377
- CVE-2025-43424
- CVE-2025-43506
- CVE-2025-43389
- CVE-2025-43469
- CVE-2025-43411
- CVE-2025-43405
- CVE-2025-43391
- CVE-2025-43393
- CVE-2025-46316
- CVE-2024-43398
- CVE-2024-49761
- CVE-2025-6442
- CVE-2025-43493
- CVE-2025-43503
- CVE-2025-43502
- CVE-2025-43406
- CVE-2025-43404
- CVE-2025-43339
- CVE-2025-43500
- CVE-2025-43335
- CVE-2025-43408
- CVE-2025-43476
- CVE-2025-30465
- CVE-2025-43414
- CVE-2025-43473
- CVE-2025-43499
- CVE-2025-43380
- CVE-2025-43477
- CVE-2025-43399
- CVE-2025-43336
- CVE-2025-43397
- CVE-2025-43409
- CVE-2025-43351
- CVE-2025-43463
- CVE-2025-32462
- CVE-2025-43334
- CVE-2025-43412
- CVE-2025-53906
- CVE-2025-43480
- CVE-2025-43458
- CVE-2025-43430
- CVE-2025-43427
- CVE-2025-43443
- CVE-2025-43441
- CVE-2025-43435
- CVE-2025-43425
- CVE-2025-43440
- CVE-2025-43438
- CVE-2025-43457
- CVE-2025-43434
- CVE-2025-43433
- CVE-2025-43431
- CVE-2025-43432
- CVE-2025-43429
- CVE-2025-43421
- CVE-2025-43392
- CVE-2025-43373
- CVE-2025-43402
- CVE-2025-43472
Frequently Asked Questions
What is the severity of CVE-2025-43508?
CVE-2025-43508 has been addressed with improved data redaction, indicating it is a high-severity logging issue that could allow unauthorized access to sensitive user data.
How do I fix CVE-2025-43508?
To fix CVE-2025-43508, update your macOS Tahoe to version 26.1 or later.
What does CVE-2025-43508 affect?
CVE-2025-43508 affects the Admin Framework and Apple Account functionalities in macOS Tahoe.
Is CVE-2025-43508 still an issue in the latest version?
No, CVE-2025-43508 has been resolved in macOS Tahoe version 26.1 and is no longer an issue in that version.
Can apps exploit CVE-2025-43508?
Yes, prior to the fix, apps could potentially exploit CVE-2025-43508 to access sensitive user data.