CVE-2025-43394

Source
https://cve.org/CVERecord?id=CVE-2025-43394
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-43394.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-43394
Published
2025-11-04T02:15:46.180Z
Modified
2026-03-14T15:04:23.582019Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1, macOS Sonoma 14.8.2. An app may be able to access protected user data.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "14.0"
            },
            {
                "fixed": "14.8.2"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "15.0"
            },
            {
                "fixed": "15.7.2"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-43394.json"