CVE-2025-43358
published 2025-09-15CVE-2025-43358: A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia…
PriorityP344high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.28%
19.6th percentile
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A shortcut may be able to bypass sandbox restrictions.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.7_and_ipados | — | — |
| apple | ios_26_and_ipados | — | — |
| apple | ios_and_ipados | < 18.7 | 18.7 |
| apple | ios_and_ipados | < 26 | 26 |
| apple | ipados | < 18.7 | 18.7 |
| apple | iphone_os | < 18.7 | 18.7 |
| apple | macos | < 14.8 | 14.8 |
| apple | macos | < 15.7 | 15.7 |
| apple | macos | < 26 | 26 |
| apple | macos | >= 14.0 < 14.8 | 14.8 |
| apple | macos | >= 15.0 < 15.7 | 15.7 |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_tahoe | — | — |
| msrc | azl3_libsass_3.6.6-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2025-43358: macOS Sonoma 14.8
vendor_apple·2025-09-15·CVSS 8.8
CVE-2025-43358 [HIGH] CVE-2025-43358: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-43358
Component: Shortcuts
Impact: A shortcut may be able to bypass sandbox restrictions
Description: A permissions issue was addressed with additional sandbox restrictions.
Apple
CVE-2025-43358: macOS Sequoia 15.7
vendor_apple·2025-09-15·CVSS 8.8
CVE-2025-43358 [HIGH] CVE-2025-43358: macOS Sequoia 15.7
Apple Security Update: About the security content of macOS Sequoia 15.7
Product: macOS Sequoia
Version: 15.7
CVE: CVE-2025-43358
Component: Shortcuts
Impact: A shortcut may be able to bypass sandbox restrictions
Description: A permissions issue was addressed with additional sandbox restrictions.
Apple
CVE-2025-43358: iOS 26 and iPadOS 26
vendor_apple·2025-09-15·CVSS 8.8
CVE-2025-43358 [HIGH] CVE-2025-43358: iOS 26 and iPadOS 26
Apple Security Update: About the security content of iOS 26 and iPadOS 26
Product: iOS 26 and iPadOS
Version: 26
CVE: CVE-2025-43358
Component: Shortcuts
Impact: A shortcut may be able to bypass sandbox restrictions
Description: A permissions issue was addressed with additional sandbox restrictions.
Apple
CVE-2025-43358: macOS Tahoe 26
vendor_apple·2025-09-15·CVSS 8.8
CVE-2025-43358 [HIGH] CVE-2025-43358: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43358
Component: Shortcuts
Impact: A shortcut may be able to bypass sandbox restrictions
Description: A permissions issue was addressed with additional sandbox restrictions.
Apple
CVE-2025-43358: iOS 18.7 and iPadOS 18.7
vendor_apple·2025-09-15·CVSS 8.8
CVE-2025-43358 [HIGH] CVE-2025-43358: iOS 18.7 and iPadOS 18.7
Apple Security Update: About the security content of iOS 18.7 and iPadOS 18.7
Product: iOS 18.7 and iPadOS
Version: 18.7
CVE: CVE-2025-43358
Component: Shortcuts
Impact: A shortcut may be able to bypass sandbox restrictions
Description: A permissions issue was addressed with additional sandbox restrictions.
Microsoft
Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS)
vendor_msrc·2023-08-08·CVSS 7.5
CVE-2022-43358 [HIGH] CWE-787 Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS)
Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update th
GHSA
GHSA-83c5-rf2w-mm9m: A permissions issue was addressed with additional sandbox restrictions
ghsa_unreviewed·2025-09-16
CVE-2025-43358 [HIGH] CWE-862 GHSA-83c5-rf2w-mm9m: A permissions issue was addressed with additional sandbox restrictions
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, iOS 18.7 and iPadOS 18.7, macOS Tahoe 26, iOS 26 and iPadOS 26. A shortcut may be able to bypass sandbox restrictions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/125108https://support.apple.com/en-us/125109https://support.apple.com/en-us/125110https://support.apple.com/en-us/125111https://support.apple.com/en-us/125112http://seclists.org/fulldisclosure/2025/Sep/49http://seclists.org/fulldisclosure/2025/Sep/53http://seclists.org/fulldisclosure/2025/Sep/54http://seclists.org/fulldisclosure/2025/Sep/55
2025-09-15
Published