---
cve: "CVE-2025-43260"
severity: "MEDIUM"
cvss: 5.1
epss: "21%"
vendor: "Apple"
kev: false
exploited: false
published: "2025-07-30 00:15:37"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T06:32:29+02:00"
---

# CVE-2025-43260

> 5.1 MEDIUM

## Beschreibung

This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to hijack entitlements granted to other privileged apps.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://support.apple.com/en-us/124149>
- <https://support.apple.com/en-us/124150>
- <http://seclists.org/fulldisclosure/2025/Jul/32>
- <http://seclists.org/fulldisclosure/2025/Jul/33>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-43260) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
