CVE-2025-43339
macOS vulnerability analysis and mitigation

Overview

CVE-2025-43339 is a sandbox access control vulnerability in Apple macOS that allows a malicious local application to access sensitive user data outside its intended sandbox restrictions. It affects macOS Tahoe versions prior to 26.1 and was fixed in macOS Tahoe 26.1, released November 3, 2025. The vulnerability was discovered by Ryan Dowd (@_rdowd) and publicly disclosed on June 10–11, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control) and stems from insufficient sandbox restrictions within the macOS Sandbox component. A locally installed malicious application can exploit this flaw to bypass the sandbox boundary and access sensitive user data that should be restricted. The attack requires low privileges and no user interaction, and is limited to local access (attack vector: local). Apple addressed the issue by implementing additional sandbox restrictions (Apple Advisory, GitHub Advisory).

Impact

Successful exploitation results in unauthorized access to sensitive user data on the affected macOS system, with a high confidentiality impact and no integrity or availability impact. A malicious app running under a low-privileged user account can escape its sandbox to read data belonging to the user that would otherwise be protected by macOS sandbox policies. There is no evidence of lateral movement capability or remote exploitation; the risk is confined to local data exposure on the affected host (Apple Advisory, GitHub Advisory).

Mitigation and workarounds

Apple has released a patch in macOS Tahoe 26.1 (released November 3, 2025), which addresses this vulnerability with additional sandbox restrictions. Users and administrators should update all affected macOS Tahoe systems to version 26.1 or later as the primary remediation. As interim measures, restricting which applications are permitted to run on affected systems and monitoring for suspicious application behavior accessing sensitive user data can reduce risk (Apple Advisory).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-43746MEDIUM6.5
  • Apple Safari logoApple Safari
  • cpe:2.3:a:apple:safari
NoYesJun 29, 2026
CVE-2026-43745MEDIUM6.5
  • Apple Safari logoApple Safari
  • pywebkitgtk
NoYesJun 29, 2026
CVE-2026-43742MEDIUM6.5
  • Apple Safari logoApple Safari
  • wpewebkit
NoYesJun 29, 2026
CVE-2026-43740MEDIUM6.5
  • Apple Safari logoApple Safari
  • webkit2gtk3-jsc-devel
NoYesJun 29, 2026
CVE-2026-43743MEDIUM4.7
  • macOS logomacOS
  • IOGPUFamily
NoYesJun 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management