-
-
-
-
4 CVE found in Apple products (macOS)
Rodolphe BRUNETTI found several vulnerabilities, patched in the latest Apple update :
CVE in Archive Utility
Archive Utility
Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An app may be able to bypass Privacy preferences
Description: This issue was addressed with improved validation of symlinks.
CVE-2025-43288: Rodolphe BRUNETTI (@eisw0lf) of Lupus Nova
CVE in MigrationKit
MigrationKit
Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An app may be able to access user-sensitive data
Description: This issue was addressed by removing the vulnerable code.
CVE-2025-43315: Rodolphe Brunetti (@eisw0lf) of Lupus Nova
CVE in Music
Music
Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An app may be able to access user-sensitive data
Description: This issue was addressed with improved entitlements.
CVE-2025-43207: Rodolphe Brunetti (@eisw0lf) of Lupus Nova, an anonymous researcher
CVE in Spotlight
Spotlight
Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An app may be able to access sensitive user data
Description: A logic issue was addressed with improved checks.
CVE-2025-24197: Rodolphe Brunetti (@eisw0lf) of Lupus Nova
Links
Apple Security Advisory macOS Tahoe 26
Apple Security Advisory macOS Sequoia 15.7
Apple Security Advisory macOS Sonoma 14.8
NIST entry CVE-2025-43288
NIST entry CVE-2025-43315
NIST entry CVE-2025-43207
NIST entry CVE-2025-24197
-
-
-
-
-
3 CVE found in Apple products (macOS & iOS)
Our vulnerability researcher Rodolphe BRUNETTI found several vulnerabilities, patched in the latest Apple update :
CVE in System Settings
System Settings
Available for: Mac Studio (2022 and later), iMac (2019 and later), Mac Pro (2019 and later), Mac Mini (2018 and later), MacBook Air (2020 and later), MacBook Pro (2018 and later), and iMac Pro (2017 and later)
Impact: An app may be able to read arbitrary files
Description: A path handling issue was addressed with improved validation.
CVE-2024-44190: Rodolphe BRUNETTI (@eisw0lf)
CVE in Mail Accounts
Mail Accounts
Available for: Mac Studio (2022 and later), iMac (2019 and later), Mac Pro (2019 and later), Mac Mini (2018 and later), MacBook Air (2020 and later), MacBook Pro (2018 and later), and iMac Pro (2017 and later)
Impact: An app may be able to access information about a user’s contacts
Description: A privacy issue was addressed with improved private data redaction for log entries.
CVE-2024-40791: Rodolphe BRUNETTI (@eisw0lf)
CVE in Siri
Siri
Available for: Mac Studio (2022 and later), iMac (2019 and later), Mac Pro (2019 and later), Mac Mini (2018 and later), MacBook Air (2020 and later), MacBook Pro (2018 and later), and iMac Pro (2017 and later)
Impact: An app may be able to access user-sensitive data
Description: A privacy issue was addressed by moving sensitive data to a more secure location.
CVE-2024-44170: K宝, LFY (@secsys), Smi1e, yulige, Cristian Dinca (icmd.tech), Rodolphe BRUNETTI (@eisw0lf)
Links
Apple Security Advisory macOS 15
Apple Security Advisory iOS 18
NIST entry CVE-2024-40791
NIST entry CVE-2024-44170
NIST entry CVE-2024-44190
-
Touch background to close