PT-2025-31302 · Apple · Ipados+4

Mickey Jin

+1

·

Published

2025-07-29

·

Updated

2025-09-07

·

CVE-2025-43220

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions iPadOS versions prior to 17.7.9 macOS Sequoia versions prior to 15.6 macOS Sonoma versions prior to 14.7.7 macOS Ventura versions prior to 13.7.7
Description The issue involves improved validation of symlinks. A malicious application may be able to access protected user data.
Recommendations Update iPadOS to version 17.7.9. Update macOS Sequoia to version 15.6. Update macOS Sonoma to version 14.7.7. Update macOS Ventura to version 13.7.7.

Fix

Link Following

Weakness Enumeration

Related Identifiers

BDU:2025-09432
CVE-2025-43220

Affected Products

Apple Macos
Ipados
Macos Sequoia
Macos Sonoma
Macos Ventura