CVE-2025-43387
7.8Apple · macOS
A permissions vulnerability in macOS allows a malicious application to gain root privileges through insufficient restrictions.
Executive summary
A critical permissions vulnerability in Apple macOS Sequoia and Tahoe allows local malicious applications to escalate privileges to root, posing a severe risk to system integrity.
Vulnerability
This is a local privilege escalation flaw where insufficient permission restrictions allow a low-privileged malicious application to execute code with root-level access. The vulnerability is categorized as an improper access control issue requiring local access by an attacker.
Business impact
The ability for a malicious application to achieve root privileges grants an attacker complete control over the affected system. This compromise can lead to full data exfiltration, the installation of persistent rootkits, and the complete bypass of all operating system security controls. Given the CVSS score of 7.8, this represents a high-severity threat that could lead to widespread system compromise within an enterprise environment.
Remediation
Immediate Action: Update all affected macOS systems to the versions specified in the vendor security advisory to apply the necessary permission restrictions.
Proactive Monitoring: Monitor system logs for unauthorized attempts to invoke elevated processes or suspicious activity originating from third-party applications.
Compensating Controls: Implement strict application control and code signing policies to prevent the execution of untrusted or unauthorized binaries on managed macOS endpoints.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a significant risk to the security posture of macOS deployments by enabling local privilege escalation. Organizations should prioritize the deployment of the vendor-supplied updates across their fleet to remediate this flaw. Failure to patch may allow attackers to bypass security boundaries and achieve full system control if a malicious application is introduced to the environment.