
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43378 is a permissions issue in Apple macOS that allows a malicious app to access sensitive user data. The vulnerability was disclosed on November 3, 2025, as part of Apple's security updates for macOS Sequoia 15.7.2 and macOS Tahoe 26.1. It affects macOS versions prior to 15.7.2 (Sequoia) and was later also addressed in macOS Tahoe 26.1. The vulnerability has a CVSS v3.1 base score of 5.5 (Medium), reflecting a local attack vector with high confidentiality impact but no integrity or availability impact (Apple Sequoia Advisory, Apple Tahoe Advisory).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), stemming from insufficient permission restrictions within the AppleMobileFileIntegrity component on macOS. An app running on the system can exploit this flaw to bypass expected access controls and read sensitive user data it should not be permitted to access. Exploitation requires local access and some degree of user interaction (e.g., running a malicious app), but does not require elevated privileges. The vulnerability was reported by an anonymous researcher and fixed by Apple with additional restrictions (Apple Sequoia Advisory, Apple Tahoe Advisory).
Successful exploitation allows a malicious application to access sensitive user data that is normally protected by macOS permission controls, resulting in a high confidentiality impact. There is no impact to system integrity or availability. The scope is limited to the local system, but the exposed data could include personal files, credentials, or other protected user information managed by the AppleMobileFileIntegrity subsystem (Apple Sequoia Advisory, Apple Tahoe Advisory).
There are no known public proof-of-concept exploits or reports of in-the-wild exploitation for CVE-2025-43378. The EPSS score is approximately 0.015% (0.000150), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).
Apple has addressed this vulnerability in macOS Sequoia 15.7.2 (released November 3, 2025) and macOS Tahoe 26.1. Users should update their macOS installations to these versions or later as soon as possible. No configuration-based workarounds have been published; upgrading to the patched release is the recommended and only known remediation (Apple Sequoia Advisory, Apple Tahoe Advisory).
The CIS published an advisory noting multiple vulnerabilities in Apple products addressed in the November 2025 update cycle, including CVE-2025-43378. The SANS Internet Storm Center also covered the Apple November 2025 patch batch. Coverage was routine and consistent with Apple's standard security update cycle, with no notable controversy or elevated concern specific to this CVE (CIS Advisory, SANS ISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."