
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43470 is a permissions vulnerability in Apple macOS affecting the Disk Images component, where a standard user may be able to view files created from a disk image belonging to an administrator. The vulnerability is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource) and was disclosed on November 3, 2025, with the fix included in macOS Tahoe 26.1. It affects all macOS Tahoe versions prior to 26.1. The CVSS v3.1 base score is 5.5 (Medium) (Apple Advisory).
The root cause is an incorrect permission assignment (CWE-732) in the macOS Disk Images subsystem, where files extracted or created from a disk image mounted by an administrator are accessible to standard (non-privileged) users due to insufficient access control restrictions. The attack vector is local, requiring low privileges and no user interaction, meaning any standard user account on the affected system could potentially read administrator-owned files derived from disk images. Apple addressed the issue by applying additional restrictions to the permission handling logic in the Disk Images component. The vulnerability was discovered and reported by Kenneth Chew (Apple Advisory).
Successful exploitation allows a standard local user to read files that should be restricted to an administrator, resulting in a high confidentiality impact with no integrity or availability impact. Sensitive data stored in administrator-created disk image files — such as configuration files, credentials, or private documents — could be exposed to unauthorized users on the same system. There is no evidence of lateral movement capability or remote exploitation potential, as the attack is confined to the local system (Apple Advisory).
Apple has patched this vulnerability in macOS Tahoe 26.1, released November 3, 2025. Users and administrators should update affected macOS Tahoe systems to version 26.1 or later via System Settings > General > Software Update. No configuration-based workaround has been published; upgrading to the patched release is the only recommended remediation (Apple Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."