CVE-2025-43468
published 2025-11-04CVE-2025-43468: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.2…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.11%
1.8th percentile
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 15.7.2 | 15.7.2 |
| apple | macos | < 26.1 | 26.1 |
| apple | macos | < 14.8.2 | 14.8.2 |
| apple | macos | >= 15.0 < 15.7.2 | 15.7.2 |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_tahoe | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2025-43468: macOS Tahoe 26.1
vendor_apple·2025-11-03·CVSS 5.5
CVE-2025-43468 [MEDIUM] CVE-2025-43468: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43468
Component: AppleMobileFileIntegrity
Impact: An app may be able to access sensitive user data
Description: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
Apple
CVE-2025-43468: macOS Sonoma 14.8.2
vendor_apple·2025-11-03·CVSS 5.5
CVE-2025-43468 [MEDIUM] CVE-2025-43468: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43468
Component: AppleMobileFileIntegrity
Impact: An app may be able to access sensitive user data
Description: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
Apple
CVE-2025-43468: macOS Sequoia 15.7.2
vendor_apple·2025-11-03·CVSS 5.5
CVE-2025-43468 [MEDIUM] CVE-2025-43468: macOS Sequoia 15.7.2
Apple Security Update: About the security content of macOS Sequoia 15.7.2
Product: macOS Sequoia
Version: 15.7.2
CVE: CVE-2025-43468
Component: AppleMobileFileIntegrity
Impact: An app may be able to access sensitive user data
Description: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
GHSA
GHSA-849v-5927-j7jq: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions
ghsa_unreviewed·2025-11-04
CVE-2025-43468 [HIGH] CWE-200 GHSA-849v-5927-j7jq: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app may be able to access sensitive user data.
Suricata
ET WEB_SPECIFIC_APPS Microsoft Configuration Manager Unauthenticated SQL Injection (CVE-2024-43468)
suricata·2025-01-27·CVSS 9.8
CVE-2024-43468 [CRITICAL] ET WEB_SPECIFIC_APPS Microsoft Configuration Manager Unauthenticated SQL Injection (CVE-2024-43468)
ET WEB_SPECIFIC_APPS Microsoft Configuration Manager Unauthenticated SQL Injection (CVE-2024-43468)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Microsoft Configuration Manager Unauthenticated SQL Injection (CVE-2024-43468)"; flow:established,to_server; http.method; content:"CCM_POST"; http.uri; content:"/ccm_system/request"; fast_pattern; http.request_body; content:"U|00|I|00|D|00|:|00|"; pcre:"/^[^\x22]{36,100}[\x3b\x26\x60\x7c\x24]/R"; reference:url,www.synacktiv.com/advisories/microsoft-configuration-manager-configmgr-2403-unauthenticated-sql-injections; reference:cve,2024-43468; classtype:web-application-attack; sid:2059681; rev:2; metadata:attack_target Server, tls_state TLSDecrypt, created_at 2025_01_27, cve CVE_2024_43468, deployment Perimeter, de
No public exploits indexed.
No writeups or analysis indexed.
2025-11-04
Published