This issue was addressed with improved validation of symlinks. This issue is fixed in visionOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1. An app may be able to break out of its sandbox.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Nov 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple iphone Os
|
|
| CPEs | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple iphone Os
|
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ios Apple ipados Apple macos Apple macos Sequoia Apple macos Sonoma Apple tvos Apple visionos Apple watchos |
|
| Vendors & Products |
Apple
Apple ios Apple ipados Apple macos Apple macos Sequoia Apple macos Sonoma Apple tvos Apple visionos Apple watchos |
Tue, 04 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Tue, 04 Nov 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This issue was addressed with improved validation of symlinks. This issue is fixed in visionOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1. An app may be able to break out of its sandbox. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published: 2025-11-04T01:15:20.321Z
Updated: 2025-11-04T15:59:52.307Z
Reserved: 2025-04-16T15:24:37.125Z
Link: CVE-2025-43448
Updated: 2025-11-04T15:59:47.805Z
Status : Analyzed
Published: 2025-11-04T02:15:50.543
Modified: 2025-11-04T17:52:07.557
Link: CVE-2025-43448
No data.