
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43518 is a logic issue in Apple's Foundation framework that allows a locally installed app to inappropriately access files through the spellcheck API. The vulnerability was discovered by Noah Gregory (wts.dev) and disclosed on December 12, 2025, when Apple released patches across multiple platforms. Affected software includes macOS Sonoma prior to 14.8.3, macOS Sequoia prior to 15.7.3, iOS and iPadOS prior to 26.2, macOS Tahoe prior to 26.2, and watchOS prior to 26.2. It carries a CVSS v3.1 base score of 3.3 (Low), assessed by CISA-ADP (Apple Advisory iOS 26.2, Apple Advisory macOS Sequoia, Apple Advisory macOS Sonoma).
The vulnerability is rooted in a logic flaw (CWE-284: Improper Access Control) within Apple's Foundation framework, specifically in how the spellcheck API handles file access. Insufficient validation checks allowed an app to leverage the spellcheck API as an unintended pathway to read files outside its normally permitted scope. Exploitation requires local access and low privileges — an attacker-controlled app running on the device can trigger the issue without any user interaction. The researcher Noah Gregory published a technical write-up at wts.dev describing the vulnerability, referred to as "DirtyDict" (wts.dev write-up, Apple Advisory macOS Sequoia).
Successful exploitation results in a limited confidentiality impact, allowing a malicious app to read files it should not have access to via the spellcheck API. There is no integrity or availability impact — the vulnerability does not enable file modification, code execution, or denial of service. The scope is constrained to the local device and the files accessible through the spellcheck API pathway, limiting the risk of lateral movement or broad data exfiltration (Apple Advisory macOS Sonoma, Apple Advisory iOS 26.2).
log show) involving the Foundation spellcheck subsystem accessing paths outside an app's expected sandbox container.fs_usage or endpoint security frameworks.Apple has released patches addressing this vulnerability across all affected platforms: macOS Sonoma 14.8.3, macOS Sequoia 15.7.3, iOS 26.2, iPadOS 26.2, macOS Tahoe 26.2, and watchOS 26.2. Users and administrators should update to these versions or later as soon as possible. No configuration-based workarounds have been published by Apple; updating to a patched release is the only recommended remediation (Apple Advisory macOS Sequoia, Apple Advisory macOS Sonoma, Apple Advisory iOS 26.2).
The vulnerability was discovered and reported by security researcher Noah Gregory (wts.dev), who published a technical write-up titled "DirtyDict" detailing the issue. The disclosure was part of Apple's December 12, 2025 security update cycle, which also addressed more severe vulnerabilities including actively exploited WebKit flaws, drawing broader media attention to the update batch. Coverage of CVE-2025-43518 specifically was limited given its low severity rating (wts.dev write-up, Apple Advisory iOS 26.2).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."