CVE-2025-43518
macOS vulnerability analysis and mitigation

Overview

CVE-2025-43518 is a logic issue in Apple's Foundation framework that allows a locally installed app to inappropriately access files through the spellcheck API. The vulnerability was discovered by Noah Gregory (wts.dev) and disclosed on December 12, 2025, when Apple released patches across multiple platforms. Affected software includes macOS Sonoma prior to 14.8.3, macOS Sequoia prior to 15.7.3, iOS and iPadOS prior to 26.2, macOS Tahoe prior to 26.2, and watchOS prior to 26.2. It carries a CVSS v3.1 base score of 3.3 (Low), assessed by CISA-ADP (Apple Advisory iOS 26.2, Apple Advisory macOS Sequoia, Apple Advisory macOS Sonoma).

Technical details

The vulnerability is rooted in a logic flaw (CWE-284: Improper Access Control) within Apple's Foundation framework, specifically in how the spellcheck API handles file access. Insufficient validation checks allowed an app to leverage the spellcheck API as an unintended pathway to read files outside its normally permitted scope. Exploitation requires local access and low privileges — an attacker-controlled app running on the device can trigger the issue without any user interaction. The researcher Noah Gregory published a technical write-up at wts.dev describing the vulnerability, referred to as "DirtyDict" (wts.dev write-up, Apple Advisory macOS Sequoia).

Impact

Successful exploitation results in a limited confidentiality impact, allowing a malicious app to read files it should not have access to via the spellcheck API. There is no integrity or availability impact — the vulnerability does not enable file modification, code execution, or denial of service. The scope is constrained to the local device and the files accessible through the spellcheck API pathway, limiting the risk of lateral movement or broad data exfiltration (Apple Advisory macOS Sonoma, Apple Advisory iOS 26.2).

Exploitation steps

  1. Develop or obtain a malicious app: Create an app that runs locally on a target Apple device (macOS, iOS, iPadOS, or watchOS) with standard low-privilege user access.
  2. Invoke the spellcheck API: Use the Foundation framework's spellcheck API in a way that exploits the logic flaw, crafting API calls that reference file paths outside the app's sandbox or permitted scope.
  3. Access restricted files: Due to insufficient access control checks in the Foundation framework, the API returns content from files the app would not normally be permitted to read.
  4. Exfiltrate data: Read and transmit the accessed file contents to an attacker-controlled destination (wts.dev write-up, Apple Advisory macOS Sequoia).

Indicators of compromise

  • Logs: Unusual file access events in system logs (e.g., unified system log via log show) involving the Foundation spellcheck subsystem accessing paths outside an app's expected sandbox container.
  • File System: Unexpected read access to sensitive files (e.g., user documents, configuration files) by apps that have no legitimate reason to access them, detectable via file access auditing tools such as fs_usage or endpoint security frameworks.
  • Process: Apps making anomalous or high-frequency calls to spellcheck-related Foundation APIs while simultaneously accessing file paths unrelated to text input (wts.dev write-up).

Mitigation and workarounds

Apple has released patches addressing this vulnerability across all affected platforms: macOS Sonoma 14.8.3, macOS Sequoia 15.7.3, iOS 26.2, iPadOS 26.2, macOS Tahoe 26.2, and watchOS 26.2. Users and administrators should update to these versions or later as soon as possible. No configuration-based workarounds have been published by Apple; updating to a patched release is the only recommended remediation (Apple Advisory macOS Sequoia, Apple Advisory macOS Sonoma, Apple Advisory iOS 26.2).

Community reactions

The vulnerability was discovered and reported by security researcher Noah Gregory (wts.dev), who published a technical write-up titled "DirtyDict" detailing the issue. The disclosure was part of Apple's December 12, 2025 security update cycle, which also addressed more severe vulnerabilities including actively exploited WebKit flaws, drawing broader media attention to the update batch. Coverage of CVE-2025-43518 specifically was limited given its low severity rating (wts.dev write-up, Apple Advisory iOS 26.2).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management