
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43257 is a sandbox escape vulnerability in Apple macOS Sequoia affecting the Archive Utility component, caused by improper handling of symlinks (CWE-59). It was disclosed by Apple on July 29, 2025, as part of the macOS Sequoia 15.6 security update, and was discovered by Mickey Jin (@patch1t). All macOS Sequoia versions prior to 15.6 are affected. The vulnerability carries a CVSS v3.1 base score of 8.7 (High) (Apple Advisory, GitHub Advisory).
The vulnerability is classified under CWE-59 (Improper Link Resolution Before File Access / 'Link Following'), specifically a symlink-following flaw in macOS's Archive Utility. An app running within a sandbox can craft or manipulate symlinks during archive extraction to cause the system to resolve file paths outside the intended sandbox boundary. The fix was implemented by improving the handling of symlinks within Archive Utility. Note: Feedly's data also references a use-after-free description (CWE-416) for a related CFNetwork CVE (CVE-2025-43222); the correct root cause for CVE-2025-43257 is the symlink-following issue in Archive Utility (Apple Advisory, GitHub Advisory).
Successful exploitation allows a sandboxed application to break out of its sandbox, potentially gaining unauthorized access to files, data, or system resources outside its permitted scope. Given the CVSS scope change (S:C) and high confidentiality and integrity impacts, an attacker could read or modify sensitive user data and potentially escalate privileges beyond the sandbox boundary. Availability impact is rated low, indicating the primary risk is unauthorized data access and integrity compromise rather than service disruption (Apple Advisory, GitHub Advisory).
~/Library, /private/var) that were not explicitly placed there by the user.Archive Utility or com.apple.archiveutility showing file operations on paths outside the expected sandbox scope; sandbox violation reports in /var/log/ or Console.app referencing Archive Utility.Apple has addressed this vulnerability in macOS Sequoia 15.6, released July 29, 2025. Users and administrators should update all affected macOS Sequoia systems to version 15.6 or later immediately. No configuration-based workaround is available; upgrading is the only remediation (Apple Advisory).
The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Apple products patched in this release could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). Community discussion on Reddit's r/pwnhub highlighted the sandbox escape potential of this CVE. General security community sentiment treats this as a routine but important patch given the sandbox escape impact, with no reports of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."