---
cve: "CVE-2025-30465"
severity: "CRITICAL"
cvss: 9.8
epss: "100%"
vendor: "Apple"
kev: false
exploited: false
published: "2025-03-31 23:15:27"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T06:58:38+02:00"
---

# CVE-2025-30465

> 9.8 CRITICAL

## Beschreibung

A permissions issue was addressed with improved validation. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sequoia 15.7.2, macOS Sonoma 14.7.5, macOS Sonoma 14.8.2, macOS Tahoe 26.1, macOS Ventura 13.7.5. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://support.apple.com/en-us/122372>
- <https://support.apple.com/en-us/122373>
- <https://support.apple.com/en-us/122374>
- <https://support.apple.com/en-us/122375>
- <https://support.apple.com/en-us/125634>
- <https://support.apple.com/en-us/125635>
- <https://support.apple.com/en-us/125636>
- <http://seclists.org/fulldisclosure/2025/Apr/10>
- <http://seclists.org/fulldisclosure/2025/Apr/5>
- <http://seclists.org/fulldisclosure/2025/Apr/8>
- <http://seclists.org/fulldisclosure/2025/Apr/9>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-30465) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
