
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43236 is a type confusion vulnerability in the Power Management component of Apple macOS that allows an attacker to cause unexpected application termination. It affects macOS Ventura versions before 13.7.7, macOS Sonoma versions before 14.7.7, and macOS Sequoia versions before 15.6. The vulnerability was disclosed by Apple on July 29, 2025, and was discovered by Dawuge of Shuffle Team. It carries a CVSS v3.1 base score of 3.3 (Low) (Apple Advisory Sequoia, Apple Advisory Sonoma, Apple Advisory Ventura, Github Advisory).
The root cause is classified as CWE-843 (Access of Resource Using Incompatible Type / 'Type Confusion'), where a resource such as a pointer or object is allocated using one type but later accessed using an incompatible type within the macOS Power Management subsystem. Apple addressed the issue with improved memory handling. Exploitation requires local access and user interaction, with no privileges required, limiting the attack surface to scenarios where a user can be induced to run a malicious application (Apple Advisory Sequoia, Github Advisory).
Successful exploitation of CVE-2025-43236 can cause unexpected termination of applications on the affected macOS system, resulting in a limited availability impact. There is no confidentiality or integrity impact associated with this vulnerability. The scope is unchanged, meaning the impact is confined to the affected component and does not enable lateral movement or data exfiltration (Github Advisory, Apple Advisory Sonoma).
Apple has released patches addressing CVE-2025-43236 in macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7, all released on July 29, 2025. Users should update their macOS systems to these versions or later via System Settings > Software Update. No configuration-based workarounds have been published by Apple (Apple Advisory Sequoia, Apple Advisory Sonoma, Apple Advisory Ventura).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."