
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43410 is a cache information disclosure vulnerability in the Notes application on Apple macOS that allows an attacker with physical access to view deleted notes. The vulnerability affects macOS Sonoma versions before 14.8.2 and macOS Sequoia versions before 15.7.2; it is also addressed in macOS Tahoe 26.2. It was disclosed on December 12, 2025, and credited to researcher Atul R V. The CVSS v3.1 base score is 2.4 (Low), reflecting the physical access requirement and limited confidentiality impact (Apple Sequoia Advisory, Apple Sonoma Advisory, Apple Tahoe Advisory).
The root cause is classified as CWE-524 (Use of Cache Containing Sensitive Information), where the macOS Notes application fails to properly purge cached data after notes are deleted. An attacker with physical access to an unlocked or accessible Mac can exploit residual cache contents to recover notes that the user believed were permanently deleted. No authentication bypass or remote vector is involved — exploitation is entirely contingent on physical proximity and access to the device. No public proof-of-concept code or detailed technical write-up has been published (Apple Sequoia Advisory, Apple Sonoma Advisory).
The primary impact is a confidentiality breach limited to the Notes application: an attacker with physical access can read deleted notes that should no longer be accessible, potentially exposing sensitive personal or business information stored by the user. There is no integrity or availability impact, and the vulnerability does not enable remote access, privilege escalation, or lateral movement. The scope is confined to the local device and the data previously stored in the Notes app (Apple Sequoia Advisory, Apple Sonoma Advisory).
~/Library/Group Containers/group.com.apple.notes/).~/Library/Group Containers/group.com.apple.notes/ or related Notes cache directories.Apple has addressed this vulnerability by improving cache handling in the Notes application. Users should update to macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, or macOS Tahoe 26.2 or later. As a general precaution, users should enable FileVault disk encryption and require a password on wake/screen lock to limit the risk of physical access attacks. No configuration-based workaround is available short of applying the patch (Apple Sequoia Advisory, Apple Sonoma Advisory, Apple Tahoe Advisory).
The CIS Security advisory noted this vulnerability as part of a broader set of Apple product vulnerabilities patched in the November/December 2025 update cycle, recommending prompt patching (CIS Advisory). No significant independent researcher commentary or notable social media discussion specific to CVE-2025-43410 has been identified, consistent with its low severity rating and physical-access-only exploitation requirement.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."