CVE-2025-43506
macOS vulnerability analysis and mitigation

Overview

CVE-2025-43506 is a logic error in the Networking component of macOS Tahoe that causes iCloud Private Relay to fail to activate when more than one user is logged in simultaneously. The vulnerability was discovered by Doug Hogan and disclosed by Apple on November 3, 2025, with the CVE formally published by NVD on December 12, 2025. It affects all versions of macOS Tahoe prior to 26.1 and is fixed in macOS Tahoe 26.1. The CVSS v3.1 base score is 7.5 (High), assessed by CISA-ADP (Apple Advisory, NVD).

Technical details

The root cause is a logic error in macOS's Networking component related to error handling when multiple user sessions are active, classified as CWE-843 (Access of Resource Using Incompatible Type / Type Confusion) by CISA-ADP. When more than one user is concurrently logged in, the error handling path fails to properly initialize or maintain the iCloud Private Relay tunnel, causing network traffic to bypass the privacy relay and potentially expose the user's real IP address and browsing activity. No authentication or user interaction is required for the condition to manifest — it occurs passively when the multi-user scenario is present (Apple Advisory, NVD).

Impact

The primary impact is a confidentiality breach: iCloud Private Relay, which is designed to mask users' IP addresses and DNS queries from network observers and websites, silently fails to activate in multi-user login scenarios. This means affected users' real IP addresses and unencrypted DNS queries may be exposed to ISPs, network operators, or websites they visit, undermining the privacy guarantees of iCloud Private Relay. There is no integrity or availability impact, and no evidence of lateral movement potential, but the exposure is passive and may go unnoticed by the user (Apple Advisory, NVD).

Mitigation and workarounds

Apple has addressed this vulnerability in macOS Tahoe 26.1, released November 3, 2025. Users running macOS Tahoe should update to version 26.1 or later via System Settings > General > Software Update. No configuration-based workaround is officially documented; however, users who rely on iCloud Private Relay for privacy and cannot immediately update should avoid using Fast User Switching or having multiple users logged in simultaneously until the patch is applied (Apple Advisory).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management