CVE-2025-43329

8.8

Apple · iOS, iPadOS, macOS, tvOS, watchOS

A sandbox escape vulnerability in multiple Apple operating systems allows a malicious application to bypass security restrictions and gain unauthorized access to system resources.

Executive summary

A critical sandbox escape vulnerability in Apple operating systems allows malicious applications to bypass security boundaries, potentially leading to full system compromise.

Vulnerability

This is a sandbox escape flaw where an application can bypass its intended security constraints. The vulnerability requires a local attacker who has already successfully installed a malicious application on the target device.

Business impact

The ability for an application to break out of its sandbox constitutes a severe security failure, as it effectively renders the platform's primary isolation mechanism useless. With a CVSS score of 8.8, this flaw enables an attacker to escalate privileges, access sensitive user data, or execute arbitrary code outside the restricted environment, posing a significant risk to organizational data integrity and device security.

Remediation

Immediate Action: Update all affected Apple devices to version 26 or later, as specified in the official Apple security advisories for each platform.

Proactive Monitoring: Monitor for unusual application behavior or unauthorized system-level calls that might indicate an attempt to bypass security policies.

Compensating Controls: Enforce strict mobile device management (MDM) policies to restrict the installation of unauthorized or unverified applications.

Exploitation status

Public Exploit Available: Unknown (no confirmed public exploit)

Analyst recommendation

Given the severity of this sandbox escape, organizations must prioritize the deployment of the version 26 updates across all managed Apple hardware. Failure to patch these devices leaves them vulnerable to malicious applications that could compromise the entire operating system environment, necessitating urgent attention from IT and security teams.

More Apple CVEs

Sources