CVE-2025-43410
macOS vulnerability analysis and mitigation

Overview

CVE-2025-43410 is a cache information disclosure vulnerability in the Notes application on Apple macOS that allows an attacker with physical access to view deleted notes. The vulnerability affects macOS Sonoma versions before 14.8.2 and macOS Sequoia versions before 15.7.2; it is also addressed in macOS Tahoe 26.2. It was disclosed on December 12, 2025, and credited to researcher Atul R V. The CVSS v3.1 base score is 2.4 (Low), reflecting the physical access requirement and limited confidentiality impact (Apple Sequoia Advisory, Apple Sonoma Advisory, Apple Tahoe Advisory).

Technical details

The root cause is classified as CWE-524 (Use of Cache Containing Sensitive Information), where the macOS Notes application fails to properly purge cached data after notes are deleted. An attacker with physical access to an unlocked or accessible Mac can exploit residual cache contents to recover notes that the user believed were permanently deleted. No authentication bypass or remote vector is involved — exploitation is entirely contingent on physical proximity and access to the device. No public proof-of-concept code or detailed technical write-up has been published (Apple Sequoia Advisory, Apple Sonoma Advisory).

Impact

The primary impact is a confidentiality breach limited to the Notes application: an attacker with physical access can read deleted notes that should no longer be accessible, potentially exposing sensitive personal or business information stored by the user. There is no integrity or availability impact, and the vulnerability does not enable remote access, privilege escalation, or lateral movement. The scope is confined to the local device and the data previously stored in the Notes app (Apple Sequoia Advisory, Apple Sonoma Advisory).

Exploitation steps

  1. Physical Access: Gain physical access to a Mac running a vulnerable version of macOS (Sonoma before 14.8.2 or Sequoia before 15.7.2).
  2. Access the Device: Interact with the device — this may require the device to be unlocked or the attacker to bypass the lock screen through other means.
  3. Navigate to Notes Cache: Access the Notes application or its underlying cache storage on the filesystem (typically located in the user's Library directory under ~/Library/Group Containers/group.com.apple.notes/).
  4. Recover Deleted Notes: Browse or read cached note data that persists after deletion due to improper cache handling, recovering content the user intended to permanently delete (Apple Sequoia Advisory, Apple Sonoma Advisory).

Indicators of compromise

  • File System: Unexpected access or modification timestamps on files within ~/Library/Group Containers/group.com.apple.notes/ or related Notes cache directories.
  • Logs: macOS Unified Log entries showing unusual access to Notes application data stores by unauthorized processes or users.
  • Process: Unexpected processes reading from the Notes application container directory outside of normal Notes app activity.

Mitigation and workarounds

Apple has addressed this vulnerability by improving cache handling in the Notes application. Users should update to macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, or macOS Tahoe 26.2 or later. As a general precaution, users should enable FileVault disk encryption and require a password on wake/screen lock to limit the risk of physical access attacks. No configuration-based workaround is available short of applying the patch (Apple Sequoia Advisory, Apple Sonoma Advisory, Apple Tahoe Advisory).

Community reactions

The CIS Security advisory noted this vulnerability as part of a broader set of Apple product vulnerabilities patched in the November/December 2025 update cycle, recommending prompt patching (CIS Advisory). No significant independent researcher commentary or notable social media discussion specific to CVE-2025-43410 has been identified, consistent with its low severity rating and physical-access-only exploitation requirement.

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management