CVE-2025-43463
macOS vulnerability analysis and mitigation

Overview

CVE-2025-43463 is a path traversal vulnerability in the StorageKit component of Apple macOS, classified under CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). A parsing issue in the handling of directory paths allows a malicious app to access sensitive user data. The vulnerability affects macOS Sonoma prior to 14.8.3, macOS Sequoia prior to 15.7.3, and macOS Tahoe prior to 26.1. It was first disclosed by Apple on November 3, 2025, with patches released on December 12, 2025, and carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Advisory Tahoe, Apple Advisory Sequoia, Apple Advisory Sonoma).

Technical details

The root cause is a path parsing flaw in macOS's StorageKit component (CWE-22: Path Traversal), where insufficient validation of directory path inputs allows an application to traverse outside its intended directory boundaries. The vulnerability is exploited locally by a low-privileged app that crafts directory path inputs to bypass path restrictions and access protected file system locations containing sensitive user data. Apple addressed the issue with improved path validation logic. The vulnerability was discovered and reported by Amy (@asentientbot) and Mickey Jin (@patch1t) (Apple Advisory Tahoe, Apple Advisory Sequoia).

Impact

Successful exploitation allows a malicious application to access sensitive user data that would otherwise be protected by macOS's file system access controls. The primary impact is a high confidentiality breach (CVSS C:H), with no direct integrity or availability impact. The vulnerability is scoped to the local system and does not inherently enable remote exploitation or lateral movement, but data exposed could include personal files, credentials, or other protected user information stored on the affected macOS system (Apple Advisory Sonoma, Apple Advisory Sequoia).

Mitigation and workarounds

Apple has released patches addressing CVE-2025-43463 in the following versions: macOS Sonoma 14.8.3, macOS Sequoia 15.7.3, and macOS Tahoe 26.1. Users and administrators should update affected macOS systems to these versions or later as soon as possible. No configuration-based workarounds have been published by Apple; upgrading to a patched release is the only recommended remediation (Apple Advisory Sonoma, Apple Advisory Sequoia, Apple Advisory Tahoe).

Community reactions

The vulnerability was noted in CIS Security advisories covering multiple Apple product vulnerabilities released in November and December 2025. The SANS Internet Storm Center also referenced the Apple security updates in diary entries around the time of disclosure. No significant independent researcher commentary or notable social media discussion specific to CVE-2025-43463 has been identified beyond standard patch tracking and vulnerability database updates.

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management