
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43339 is a sandbox access control vulnerability in Apple macOS that allows a malicious local application to access sensitive user data outside its intended sandbox restrictions. It affects macOS Tahoe versions prior to 26.1 and was fixed in macOS Tahoe 26.1, released November 3, 2025. The vulnerability was discovered by Ryan Dowd (@_rdowd) and publicly disclosed on June 10–11, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Advisory, GitHub Advisory).
The vulnerability is classified as CWE-284 (Improper Access Control) and stems from insufficient sandbox restrictions within the macOS Sandbox component. A locally installed malicious application can exploit this flaw to bypass the sandbox boundary and access sensitive user data that should be restricted. The attack requires low privileges and no user interaction, and is limited to local access (attack vector: local). Apple addressed the issue by implementing additional sandbox restrictions (Apple Advisory, GitHub Advisory).
Successful exploitation results in unauthorized access to sensitive user data on the affected macOS system, with a high confidentiality impact and no integrity or availability impact. A malicious app running under a low-privileged user account can escape its sandbox to read data belonging to the user that would otherwise be protected by macOS sandbox policies. There is no evidence of lateral movement capability or remote exploitation; the risk is confined to local data exposure on the affected host (Apple Advisory, GitHub Advisory).
Apple has released a patch in macOS Tahoe 26.1 (released November 3, 2025), which addresses this vulnerability with additional sandbox restrictions. Users and administrators should update all affected macOS Tahoe systems to version 26.1 or later as the primary remediation. As interim measures, restricting which applications are permitted to run on affected systems and monitoring for suspicious application behavior accessing sensitive user data can reduce risk (Apple Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."