
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43497 is a sandbox escape vulnerability in the BackBoardServices component of Apple macOS Tahoe, where an access issue allows an app to break out of its sandbox. The vulnerability was disclosed by Apple on November 3, 2025, as part of the macOS Tahoe 26.1 security update, and was reported by an anonymous researcher. It affects all versions of macOS Tahoe prior to 26.1. The CVSS v3.1 base score is 5.2 (Medium), as assessed by CISA-ADP (Apple Advisory).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the affected component fails to perform adequate authorization checks before granting access to a resource or functionality (Apple Advisory). Apple addressed the issue by implementing additional sandbox restrictions within the BackBoardServices framework. The attack vector is local, requiring low privileges and no user interaction, but the scope is changed — indicating the vulnerability can affect resources beyond the vulnerable component's security scope. No public technical write-ups or proof-of-concept code have been identified at this time.
Successful exploitation allows a malicious application running within the macOS sandbox to escape its restricted execution environment, potentially gaining access to resources and system components outside its intended scope. This could lead to limited confidentiality and integrity impacts, as the CVSS assessment indicates low impact on both dimensions with no availability impact. While not a full system compromise on its own, a sandbox escape can serve as a stepping stone for privilege escalation or access to sensitive user data when chained with other vulnerabilities (Apple Advisory).
Apple has addressed this vulnerability in macOS Tahoe 26.1, released November 3, 2025. Users running macOS Tahoe should update to version 26.1 or later immediately via System Settings > General > Software Update. No configuration-based workarounds have been published by Apple. Organizations should prioritize patching macOS endpoints running the affected Tahoe release (Apple Advisory).
The vulnerability was included in Apple's macOS Tahoe 26.1 security advisory alongside numerous other fixes, and was noted by CIS in their advisory on multiple Apple vulnerabilities that could allow for arbitrary code execution. No significant independent researcher commentary or notable social media discussion specific to CVE-2025-43497 has been identified (CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."