cbcvebase.
CVE-2025-43358
published 2025-09-15

CVE-2025-43358: A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia…

PriorityP344high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.28%
19.6th percentile
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A shortcut may be able to bypass sandbox restrictions.

Affected

15 ranges
VendorProductVersion rangeFixed in
appleios_18.7_and_ipados
appleios_26_and_ipados
appleios_and_ipados< 18.718.7
appleios_and_ipados< 2626
appleipados< 18.718.7
appleiphone_os< 18.718.7
applemacos< 14.814.8
applemacos< 15.715.7
applemacos< 2626
applemacos>= 14.0 < 14.814.8
applemacos>= 15.0 < 15.715.7
applemacos_sequoia
applemacos_sonoma
applemacos_tahoe
msrcazl3_libsass_3.6.6-1_on_azure_linux_3.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.