CVE-2025-43414

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
04/11/2025
Last modified:
17/12/2025

Description

A permissions issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1, macOS Sonoma 14.8.2. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* 14.8.2 (excluding)
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* 15.0 (including) 15.7.2 (excluding)