
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43473 is an information disclosure vulnerability in the Shortcuts component of Apple macOS that allows a locally installed app to access sensitive user data. The issue stems from improper state management and is fixed in macOS Tahoe 26.1. It was disclosed by Apple on November 3, 2025, and credited to researcher Kirin (@Pwnrin). The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Advisory, NVD).
The vulnerability is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and arises from a state management flaw in the macOS Shortcuts framework. A locally installed app with low privileges can exploit this flaw to access sensitive user data that should be protected by the operating system's privacy controls. No user interaction is required for exploitation, and the attack is limited to the local system scope. Apple addressed the issue with improved state management in macOS Tahoe 26.1 (Apple Advisory, NVD).
Successful exploitation allows a malicious app running with standard user privileges to access sensitive user data that would otherwise be protected by macOS privacy mechanisms. The impact is limited to confidentiality — there is no integrity or availability impact. The vulnerability does not enable remote exploitation or direct lateral movement, but unauthorized access to sensitive data (such as personal files or credentials accessible via Shortcuts) could facilitate further attacks (Apple Advisory, NVD).
Apple has released a patch in macOS Tahoe 26.1, which addresses the vulnerability through improved state management in the Shortcuts component. Users and administrators should update to macOS Tahoe 26.1 or later as soon as possible. No official workaround has been published for systems that cannot be immediately updated (Apple Advisory).
The vulnerability was reported by security researcher Kirin (@Pwnrin), who is credited in Apple's official security advisory. The SANS Internet Storm Center noted the macOS Tahoe 26.1 release as part of broader Apple patch coverage. No significant independent technical write-ups or widespread community discussion specific to CVE-2025-43473 have been identified (Apple Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."