CVE-2025-43252

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
30/07/2025
Last modified:
03/11/2025

Description

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.6. A website may be able to access sensitive user data when resolving symlinks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* 15.6 (excluding)