Exposure of sensitive information to an unauthorized actor in macOS - CVE-2025-43259
Published: July 30, 2025
Vulnerability identifier: #VU113507
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-43259
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker with physical access to the system to gain access to sensitive information.
The vulnerability exists due to excessive data output in WindowServer. An attacker with physical access to the system can view sensitive user information.
Affected software
macOS
How to mitigate CVE-2025-43259
Install update from vendor's website.
macOS - addressed in versions 15.6 24G84, 13.7.7 22H722, 14.7.7 23H723