CVE-2025-43448

T

his issue was addressed with improved validation of symlinks. This issue is fixed in tvOS 26.1, watchOS 26.1, macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1, iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, visionOS 26.1. An app may be able to break out of its sandbox.

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

17 Dec 2025, 21:16

Type Values Removed Values Added
References
  • () https://support.apple.com/en-us/125632 -
  • () https://support.apple.com/en-us/125634 -
  • () https://support.apple.com/en-us/125635 -
  • () https://support.apple.com/en-us/125636 -
  • () https://support.apple.com/en-us/125637 -
  • () https://support.apple.com/en-us/125638 -
  • () https://support.apple.com/en-us/125639 -
Summary (en) This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An app may be able to break out of its sandbox. (en) This issue was addressed with improved validation of symlinks. This issue is fixed in tvOS 26.1, watchOS 26.1, macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1, iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, visionOS 26.1. An app may be able to break out of its sandbox.

05 Nov 2025, 19:15

Type Values Removed Values Added
References
  • {'url': 'https://support.apple.com/en-us/125632', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': '[email protected]'}
  • {'url': 'https://support.apple.com/en-us/125635', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': '[email protected]'}
  • {'url': 'https://support.apple.com/en-us/125636', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': '[email protected]'}
  • {'url': 'https://support.apple.com/en-us/125637', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': '[email protected]'}
  • {'url': 'https://support.apple.com/en-us/125638', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': '[email protected]'}
  • {'url': 'https://support.apple.com/en-us/125639', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': '[email protected]'}
  • () https://support.apple.com/en-us/125633 -
Summary (en) This issue was addressed with improved validation of symlinks. This issue is fixed in visionOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1. An app may be able to break out of its sandbox. (en) This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An app may be able to break out of its sandbox.

05 Nov 2025, 15:15

Type Values Removed Values Added
CWE CWE-284 CWE-59
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 6.3
References () https://support.apple.com/en-us/125632 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/125632 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/125635 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/125635 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/125636 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/125636 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/125637 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/125637 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/125638 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/125638 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/125639 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/125639 - Release Notes, Vendor Advisory

04 Nov 2025, 17:52

Type Values Removed Values Added
First Time Apple ipados
Apple watchos
Apple tvos
Apple
Apple macos
Apple visionos
Apple iphone Os
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
References () https://support.apple.com/en-us/125632 - () https://support.apple.com/en-us/125632 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/125635 - () https://support.apple.com/en-us/125635 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/125636 - () https://support.apple.com/en-us/125636 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/125637 - () https://support.apple.com/en-us/125637 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/125638 - () https://support.apple.com/en-us/125638 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/125639 - () https://support.apple.com/en-us/125639 - Vendor Advisory, Release Notes

04 Nov 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-284

04 Nov 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-04 02:15

Updated : 2025-12-17 21:16


NVD link : CVE-2025-43448

Mitre link : CVE-2025-43448

CVE.ORG link : CVE-2025-43448


JSON object : View

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')