CVE-2025-43351
- EPSS 0.01%
- Veröffentlicht 12.12.2025 20:56:23
- Zuletzt bearbeitet 15.12.2025 22:00:46
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.
CVE-2025-43516
- EPSS 0.01%
- Veröffentlicht 12.12.2025 20:56:22
- Zuletzt bearbeitet 17.12.2025 21:16:10
A session management issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3. A user with Voice Control enabled may be able to transcribe another user's activity.
CVE-2025-43404
- EPSS 0.01%
- Veröffentlicht 12.12.2025 20:56:21
- Zuletzt bearbeitet 15.12.2025 22:03:51
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
CVE-2025-43393
- EPSS 0.01%
- Veröffentlicht 12.12.2025 20:56:20
- Zuletzt bearbeitet 15.12.2025 22:03:07
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to break out of its sandbox.
CVE-2025-43517
- EPSS 0.02%
- Veröffentlicht 12.12.2025 20:56:19
- Zuletzt bearbeitet 17.12.2025 21:16:10
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3. An app may be able to access protected user data.
CVE-2025-43464
- EPSS 0.1%
- Veröffentlicht 12.12.2025 20:56:18
- Zuletzt bearbeitet 15.12.2025 22:06:54
A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Tahoe 26.1. Visiting a website may lead to an app denial-of-service.
CVE-2025-43521
- EPSS 0.01%
- Veröffentlicht 12.12.2025 20:56:17
- Zuletzt bearbeitet 17.12.2025 21:16:10
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Tahoe 26.2, macOS Sequoia 15.7.3. An app may be able to access sensitive user data.
CVE-2025-14174
- EPSS 0.87%
- Veröffentlicht 12.12.2025 19:20:41
- Zuletzt bearbeitet 15.12.2025 15:16:08
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CVE-2025-31266
- EPSS 0.03%
- Veröffentlicht 21.11.2025 21:22:24
- Zuletzt bearbeitet 26.11.2025 14:32:34
A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window.
CVE-2025-43374
- EPSS 0.04%
- Veröffentlicht 21.11.2025 21:22:23
- Zuletzt bearbeitet 26.11.2025 14:32:59
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, visionOS 2.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, macOS Sequoia 15.5, watchOS 11.5. An attacker in physical prox...