CVE-2025-43358

8.8

Apple · iOS, iPadOS, and macOS

A permissions vulnerability in Apple products allows a shortcut to bypass sandbox restrictions, potentially leading to unauthorized system access.

Executive summary

A critical sandbox bypass vulnerability in Apple iOS, iPadOS, and macOS allows local attackers to exceed intended permissions, posing a significant risk to system integrity.

Vulnerability

The flaw involves a permissions issue where a shortcut can bypass sandbox restrictions. Based on the CVSS vector (PR:L), this requires a local attacker with low privileges to execute the malicious shortcut.

Business impact

The ability to bypass sandbox restrictions allows an attacker to execute code or access data outside of the intended security boundaries of the application. Given the CVSS score of 8.8, this vulnerability carries a high risk of total system compromise, including unauthorized access to sensitive user data or system-level functions. Failure to remediate could lead to significant privacy breaches and loss of device control.

Remediation

Immediate Action: Update all affected Apple devices to the patched versions: iOS 18.7, iPadOS 18.7, iOS 26, iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, or macOS Tahoe 26.

Proactive Monitoring: Review system and application logs for unexpected shortcut execution patterns or unauthorized attempts to access protected file paths.

Compensating Controls: Limit the installation of untrusted shortcuts from non-verified sources until the system updates can be deployed to all managed endpoints.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

This vulnerability represents a significant security gap in Apple's sandbox architecture. Security teams should prioritize the deployment of the mentioned updates across the entire device fleet. Given the potential for total impact, testing and verification of the patch should be expedited to minimize the window of exposure.

More Apple CVEs

Sources