Rodolphe BRUNETTI found several vulnerabilities, patched in the latest Apple update :
CVE in Archive Utility
Archive Utility
Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An app may be able to bypass Privacy preferences
Description: This issue was addressed with improved validation of symlinks.CVE-2025-43288: Rodolphe BRUNETTI (@eisw0lf) of Lupus Nova
CVE in MigrationKit
MigrationKit
Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An app may be able to access user-sensitive data
Description: This issue was addressed by removing the vulnerable code.CVE-2025-43315: Rodolphe Brunetti (@eisw0lf) of Lupus Nova
CVE in Music
Music
Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An app may be able to access user-sensitive data
Description: This issue was addressed with improved entitlements.CVE-2025-43207: Rodolphe Brunetti (@eisw0lf) of Lupus Nova, an anonymous researcher
CVE in Spotlight
Spotlight
Available for: Mac Studio (2022 and later), iMac (2020 and later), Mac Pro (2019 and later), Mac mini (2020 and later), MacBook Air with Apple silicon (2020 and later), MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), and MacBook Pro with Apple silicon (2020 and later)
Impact: An app may be able to access sensitive user data
Description: A logic issue was addressed with improved checks.CVE-2025-24197: Rodolphe Brunetti (@eisw0lf) of Lupus Nova