
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43471 is a sensitive data exposure vulnerability in the Admin Framework component of Apple macOS Tahoe. The flaw allows a locally installed app to access sensitive user data without proper authorization. It affects all versions of macOS Tahoe prior to 26.1 and was fixed in macOS Tahoe 26.1, released November 3, 2025. The vulnerability was discovered by security researcher Gergely Kalman (@gergely_kalman) and carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Advisory).
The vulnerability is classified under CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere), indicating that the Admin Framework component failed to adequately restrict access to sensitive system or user data (Apple Advisory). Apple's description states the issue was addressed with "improved checks," suggesting insufficient input or access validation allowed an app to bypass intended data access controls. Exploitation requires local access and low privileges (no user interaction needed), making it exploitable by any app running under a standard user account on an affected macOS Tahoe system. No public technical write-up or proof-of-concept code has been identified at this time.
Successful exploitation allows a malicious or compromised application to read sensitive user data that should be protected by macOS access controls within the Admin Framework. The impact is limited to confidentiality — there is no integrity or availability impact. While the scope is confined to the local system, unauthorized access to sensitive user data could facilitate credential theft, privacy violations, or serve as a stepping stone for further privilege escalation when chained with other vulnerabilities (Apple Advisory).
Apple has addressed this vulnerability in macOS Tahoe 26.1, released November 3, 2025. Users and administrators should update all affected macOS Tahoe systems to version 26.1 or later as the primary remediation. No configuration-based workarounds have been published by Apple. Organizations should prioritize patching systems where untrusted or third-party applications are regularly executed (Apple Advisory).
The SANS Internet Storm Center noted the macOS Tahoe 26.1 release as part of broader Apple patch coverage. The CIS Security advisory highlighted multiple vulnerabilities in Apple products patched in this release, including CVE-2025-43471, recommending prompt updates. No significant individual researcher commentary or social media discussion specific to this CVE has been identified beyond standard patch reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."