CVE-2025-43451
published 2026-05-26CVE-2025-43451: A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.14%
3.4th percentile
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 26 | 26 |
| apple | macos | < 26.0 | 26.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple macOS up to 25 App permission
vuldb·2026-07-21·CVSS 5.5
CVE-2025-43451 [MEDIUM] Apple macOS up to 25 App permission
A vulnerability categorized as critical has been discovered in Apple macOS up to 25. This issue affects some unknown processing of the component App Handler. Executing a manipulation can lead to permission issues.
This vulnerability is tracked as CVE-2025-43451. The attack is restricted to local execution. No exploit exists.
It is advisable to upgrade the affected component.
GHSA
GHSA-3mgh-5qm5-mmhj: A permissions issue was addressed by removing the vulnerable code
ghsa_unreviewed·2026-05-27
CVE-2025-43451 [MEDIUM] CWE-284 GHSA-3mgh-5qm5-mmhj: A permissions issue was addressed by removing the vulnerable code
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.
Suricata
ET EXPLOIT NTLM Hash Disclosure via InternetShortcut File Inbound with UNC Path Inbound (CVE-2024-43451)
suricata·2025-05-13·CVSS 6.5
CVE-2024-43451 [MEDIUM] ET EXPLOIT NTLM Hash Disclosure via InternetShortcut File Inbound with UNC Path Inbound (CVE-2024-43451)
ET EXPLOIT NTLM Hash Disclosure via InternetShortcut File Inbound with UNC Path Inbound (CVE-2024-43451)
Rule: alert tcp any any -> $HOME_NET any (msg:"ET EXPLOIT NTLM Hash Disclosure via InternetShortcut File Inbound with UNC Path Inbound (CVE-2024-43451)"; flow:established,to_client; file.data; content:"|5b|InternetShortcut"; fast_pattern; pcre:"/^(?:\x2e[AW])\x5d/R"; content:"|3d 5c 5c 5c 5c|"; reference:url,research.checkpoint.com/2025/cve-2025-24054-ntlm-exploit-in-the-wild/; reference:cve,2024-43451; classtype:attempted-user; sid:2062313; rev:1; metadata:attack_target Client_Endpoint, created_at 2025_05_13, cve CVE_2024_43451, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2025_05_13
No public exploits indexed.
No writeups or analysis indexed.
2026-05-26
Published