CVE-2025-43252
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.6. A website may be able to access sensitive user data when resolving symlinks.
- Affected products
- Apple Macos
- Apple Macos
- < 15.6
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.5% (40th percentile)
- Weakness
- CWE-59
- NVD status
- Modified
- Published
- 2025-07-29
CVE-2025-43252 at NVD
1 known exploit for CVE-2025-43252
Proof-of-concept code and exploit modules indexed by Sploitus