This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected user data.
Metrics
Affected Vendors & Products
References
History
Thu, 31 Jul 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
Thu, 31 Jul 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-59 | |
Metrics |
cvssV3_1
|
Wed, 30 Jul 2025 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apple
Apple ipados Apple macos Apple macos Sequoia Apple macos Sonoma Apple macos Ventura |
|
Vendors & Products |
Apple
Apple ipados Apple macos Apple macos Sequoia Apple macos Sonoma Apple macos Ventura |
Tue, 29 Jul 2025 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected user data. | |
References |
|

Status: PUBLISHED
Assigner: apple
Published: 2025-07-29T23:29:28.537Z
Updated: 2025-07-31T17:56:39.669Z
Reserved: 2025-04-16T15:24:37.090Z
Link: CVE-2025-43220

Updated: 2025-07-30T13:28:12.192Z

Status : Analyzed
Published: 2025-07-30T00:15:34.053
Modified: 2025-07-31T20:49:32.343
Link: CVE-2025-43220

No data.