CVE-2025-43187
macOS vulnerability analysis and mitigation

Overview

CVE-2025-43187 is a vulnerability in the macOS Disk Images component (hdiutil) that allows a local attacker with low privileges to unexpectedly execute arbitrary code. The flaw was addressed by removing the vulnerable code, as described in Apple's security advisories released on July 29, 2025. Affected versions include macOS Sequoia prior to 15.6, macOS Sonoma prior to 14.7.7, and macOS Ventura prior to 13.7.7. It carries a CVSS v3.1 base score of 7.8 (High) (Apple Advisory 124149, Apple Advisory 124150, Apple Advisory 124151). The vulnerability was discovered and reported by 风沐云烟 (@binary_fmyy) and Minghao Lin (@Y1nKoc).

Technical details

The vulnerability resides in the macOS Disk Images subsystem, specifically in code invoked when running hdiutil commands. Apple's fix consisted of removing the vulnerable code entirely rather than patching it, suggesting the affected code path was unnecessary or could be safely eliminated. The attack vector is local, requires low privileges, and no user interaction, indicating that a locally running application or process could trigger arbitrary code execution simply by invoking an hdiutil command under certain conditions. No specific CWE classification has been publicly assigned, but the nature of the flaw — unintended code execution triggered by a system command — is consistent with unsafe code execution or improper input handling patterns (Apple Advisory 124149, Apple Advisory 124150, Apple Advisory 124151).

Impact

Successful exploitation of CVE-2025-43187 could allow a local attacker or malicious application to execute arbitrary code on the affected macOS system, with potential impacts to confidentiality, integrity, and availability — all rated High in the CVSS scoring. An attacker who can run processes on the system (e.g., via a malicious app) could leverage this vulnerability to escalate privileges, access sensitive data, or compromise system integrity. The scope is limited to the local system, but combined with other vulnerabilities, it could facilitate privilege escalation or lateral movement within a macOS environment (Apple Advisory 124149, Apple Advisory 124150).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-43187 as of the available data. The EPSS score is very low at approximately 0.017%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Apple Advisory 124149).

Mitigation and workarounds

Apple has released patches addressing CVE-2025-43187 in macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7, all released on July 29, 2025. The fix involved removing the vulnerable code from the Disk Images component. Users and administrators should update their macOS systems to the patched versions as soon as possible. No alternative workarounds have been published by Apple (Apple Advisory 124149, Apple Advisory 124150, Apple Advisory 124151).

Community reactions

The vulnerability was part of a large batch of approximately 95 security fixes Apple released across its product line on July 29, 2025, which drew broad coverage from security news outlets and aggregators. The SANS Internet Storm Center noted the release in a diary entry, and CIS published an advisory highlighting multiple vulnerabilities in Apple products that could allow arbitrary code execution. No specific researcher commentary or notable social media discussion focused exclusively on CVE-2025-43187 has been identified beyond standard vulnerability tracking and aggregation (CIS Advisory).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65400CRITICAL9.8
  • macOS logomacOS
  • Screen Sharing
NoYesAug 06, 2026
CVE-2026-64775CRITICAL9.8
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774CRITICAL9.8
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64783HIGH8.8
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776MEDIUM5.5
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management