This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://support.apple.com/en-us/122373 |
|
History
Sat, 13 Jun 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Symbolic Link Handling in macOS Allows Potential Data Exposure |
Sat, 13 Jun 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Symlink Traversal Exploits Protected User Data | |
| Weaknesses | CWE-22 CWE-284 |
Fri, 12 Jun 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-61 | |
| Metrics |
cvssV3_1
|
Thu, 11 Jun 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Symlink Traversal Exploits Protected User Data | |
| Weaknesses | CWE-22 CWE-284 |
Thu, 11 Jun 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | macOS Symlink Handling Exploit Enables Access to Protected User Data | |
| Weaknesses | CWE-22 CWE-284 |
Thu, 11 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | macOS Symlink Handling Exploit Enables Access to Protected User Data | |
| Weaknesses | CWE-22 CWE-284 |
Thu, 11 Jun 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple macos |
|
| Vendors & Products |
Apple
Apple macos |
Thu, 11 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published: 2026-06-11T18:47:40.718Z
Updated: 2026-06-12T21:22:38.449Z
Reserved: 2025-04-16T15:24:37.101Z
Link: CVE-2025-43278
Updated: 2026-06-12T21:22:34.915Z
Status : Undergoing Analysis
Published: 2026-06-11T19:16:33.393
Modified: 2026-06-12T22:16:47.710
Link: CVE-2025-43278
No data.