This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to hijack entitlements granted to other privileged apps.
                
            References
                    | Link | Resource | 
|---|---|
| https://support.apple.com/en-us/124149 | Release Notes Vendor Advisory | 
| https://support.apple.com/en-us/124150 | Release Notes Vendor Advisory | 
| http://seclists.org/fulldisclosure/2025/Jul/32 | |
| http://seclists.org/fulldisclosure/2025/Jul/33 | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    03 Nov 2025, 20:18
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
        
        
  | 
01 Aug 2025, 14:33
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://support.apple.com/en-us/124149 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/124150 - Release Notes, Vendor Advisory | |
| CPE | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | |
| First Time | 
        
        Apple
         Apple macos  | 
30 Jul 2025, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
        
        
  | 
|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 5.1  | 
| CWE | CWE-266 | 
30 Jul 2025, 00:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-07-30 00:15
Updated : 2025-11-03 20:18
NVD link : CVE-2025-43260
Mitre link : CVE-2025-43260
CVE.ORG link : CVE-2025-43260
JSON object : View
Products Affected
                apple
- macos
 
CWE
                
                    
                        
                        CWE-266
                        
            Incorrect Privilege Assignment
