CVE-2025-43530
macOS vulnerability analysis and mitigation

Overview

CVE-2025-43530 is a macOS VoiceOver vulnerability that allows a locally installed app to access sensitive user data by bypassing Apple's Transparency, Consent, and Control (TCC) privacy framework. Discovered and reported by Mickey Jin (@patch1t), it was disclosed and patched on December 12, 2025. The vulnerability affects macOS Sonoma versions before 14.8.3, macOS Sequoia versions before 15.7.3, macOS Tahoe before 26.2, and iOS/iPadOS before 18.7.3. It carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Sequoia Advisory, Apple Sonoma Advisory).

Technical details

The vulnerability is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and was addressed with improved input/permission checks in the VoiceOver component (Apple Sequoia Advisory). The root cause involves insufficient validation that allowed a malicious app to exploit a private API accessible through VoiceOver to bypass TCC protections — Apple's system for controlling app access to sensitive user data such as contacts, photos, and location — without triggering a user permission prompt (SecurityOnline). Exploitation requires local access with low privileges and no user interaction, making it suitable for a malicious app distributed through or sideloaded onto a target device. A public proof-of-concept was published by researcher Mickey Jin on GitHub (GitHub PoC).

Impact

Successful exploitation allows a malicious app to silently access sensitive user data — including data protected by TCC such as contacts, photos, calendar entries, and other private information — without presenting any authorization prompt to the user (Apple Sequoia Advisory, CyberSecurityNews). The impact is limited to confidentiality (no integrity or availability impact), but the silent, prompt-free nature of the bypass makes it particularly dangerous for targeted surveillance or data exfiltration scenarios. The vulnerability affects macOS and iOS/iPadOS devices running unpatched versions.

Exploitation steps

  1. Develop or obtain a malicious app: Create or acquire a macOS/iOS app that abuses the private VoiceOver API to access TCC-protected data without triggering user permission prompts.
  2. Install the app on the target device: Distribute the malicious app via the App Store, enterprise distribution, or sideloading onto a device running a vulnerable version (macOS Sonoma < 14.8.3, macOS Sequoia < 15.7.3, iOS/iPadOS < 18.7.3).
  3. Invoke the private VoiceOver API: The app calls the undocumented/private API exposed through the VoiceOver accessibility component, which bypasses the standard TCC permission check flow.
  4. Access sensitive user data silently: Without any user-facing authorization dialog, the app reads TCC-protected data (e.g., contacts, photos, calendar) and exfiltrates or logs it for the attacker (GitHub PoC, SecurityOnline).

Indicators of compromise

  • File System: Presence of unsigned or suspicious apps in /Applications or user-level app directories that request accessibility or VoiceOver-related entitlements without legitimate purpose.
  • Logs: Unexpected TCC database access entries in ~/Library/Application Support/com.apple.TCC/TCC.db for apps that were never granted explicit user permission; macOS Unified Log entries showing VoiceOver API calls from non-accessibility apps.
  • Process: Unusual processes invoking VoiceOver or accessibility APIs (e.g., axserver, VoiceOver) spawned by non-system, non-accessibility applications.
  • Network: Outbound connections from apps that have no legitimate need for network access, potentially exfiltrating harvested user data shortly after installation (SecurityOnline).

Mitigation and workarounds

Apple has released patches addressing CVE-2025-43530 in macOS Sonoma 14.8.3, macOS Sequoia 15.7.3, macOS Tahoe 26.2, and iOS/iPadOS 18.7.3 — all released December 12, 2025 (Apple Sequoia Advisory, Apple Sonoma Advisory, Apple iOS Advisory). Users should update their devices to these versions or later immediately via System Settings > Software Update (macOS) or Settings > General > Software Update (iOS/iPadOS). No configuration-based workaround is available; patching is the only remediation. Organizations should also audit installed apps for suspicious use of accessibility or VoiceOver APIs.

Community reactions

The vulnerability received notable attention from the security research community after Mickey Jin published a public PoC on GitHub, with discussion spreading across Reddit's r/blueteamsec and Bluesky (Reddit). Security outlets including CyberSecurityNews, GBHackers, and eSecurity Planet covered the TCC bypass angle, emphasizing the silent, prompt-free nature of the exploit as particularly concerning for user privacy (CyberSecurityNews, GBHackers). The NCSC CTO weekly summary also highlighted the vulnerability as noteworthy for defenders (NCSC CTO Summary). CIS issued an advisory noting multiple Apple vulnerabilities in the same patch batch could allow arbitrary code execution (CIS Advisory).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management