MEDIUM 5.5

CVE-2025-30459: macOS Privacy Vulnerability Allowing Unauthorized Sensitive Data Access

CVE-2025-30459 is a privacy vulnerability affecting macOS that could allow an app to access sensitive user data without appropriate restrictions. Apple addressed this by removing the vulnerable code path in macOS Sequoia 15.4. The issue requires local access and an already-installed application to exploit, limiting its immediate risk to targeted or supply-chain scenarios.

Source data · NVD / CISA · public domain

CVSS
3.1 · 5.5 MEDIUM · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
CWE-359
Affected products
1 configuration(s)
Published / Modified
2026-06-11 / 2026-06-17

NVD description (verbatim)

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

This vulnerability stems from inadequate privacy controls that permitted unauthorized access to sensitive user data (CWE-359: Improper Restriction of Rendered UI Layers or Frames). The attack vector is local, requiring no user interaction once a malicious or compromised app is present on the system. Apple's remediation involved removing the vulnerable code rather than patching it, indicating the affected functionality was non-essential. The CVSS v3.1 score of 5.5 reflects the confidentiality impact balanced against the requirement for local privileges and prior application installation.

Business impact

For enterprises managing macOS endpoints, this vulnerability poses a moderate insider-threat or supply-chain risk. If an employee installs a trojanized third-party application, it could exfiltrate sensitive data without explicit user awareness. The impact is primarily confidential—no integrity or availability compromise is expected. Organizations relying on macOS for handling regulated data (healthcare, finance, legal) should prioritize patching to maintain compliance and user privacy assurance.

Affected systems

macOS Sequoia versions prior to 15.4 are vulnerable. Users and administrators should verify their macOS build number (System Settings > General > About) and compare against the patched version. Earlier macOS versions may also be affected; organizations should check Apple's official security advisory for extended version coverage.

Exploitability

This vulnerability requires a local attacker and local privileges, making opportunistic exploitation unlikely in well-managed environments. However, it is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating no evidence of active, widespread exploitation at the time of publication. Supply-chain or targeted attacks delivering malicious apps remain the primary realistic threat vector.

Remediation

The definitive fix is upgrading to macOS Sequoia 15.4 or later. Users should enable automatic macOS updates in System Settings > General > Software Update to receive patches promptly. Organizations should test the update in a pilot environment before enterprise-wide rollout to ensure compatibility with line-of-business applications.

Patch guidance

Apple has released macOS Sequoia 15.4, which removes the vulnerable code entirely. Verify the patch availability through Apple's official security updates page. If your environment spans multiple macOS versions, request a security advisory from Apple to confirm whether older OS versions receive backported fixes or are supported through extended security updates.

Detection guidance

Monitor for suspicious third-party application installations on macOS devices using Mobile Device Management (MDM) solutions or endpoint detection and response (EDR) platforms. Review app-level privacy permissions in System Settings > Privacy & Security and audit any apps with unusual data access rights. Implement application whitelisting policies to restrict installation of unapproved software.

Why prioritize this

While the CVSS score is moderate (5.5) and exploit evidence is absent, the privacy-focused nature of this vulnerability and its applicability to data-sensitive organizations warrant timely patching within 30–60 days. Prioritize systems handling regulated or confidential information and those with weaker application controls.

Risk score, explained

A CVSS v3.1 score of 5.5 (MEDIUM) reflects a high confidentiality impact tempered by the requirement for local privileges and prior application installation. The lack of integrity or availability impact further moderates the score. In real-world risk contexts, the absence of known exploitation and the straightforward mitigation path (removing the vulnerable code) lower operational urgency but not remediation importance.

Frequently asked questions

Is this vulnerability being actively exploited?

No. CVE-2025-30459 is not listed on CISA's Known Exploited Vulnerabilities catalog, and there is no public evidence of active, widespread exploitation as of the publication date. Threat actors may develop exploits over time, so timely patching remains important.

Do I need to update all my Macs immediately?

No. Prioritize macOS devices that handle sensitive data, are used by high-value targets, or run third-party applications from less-trusted sources. Standard office machines can be updated on a normal IT schedule within 30–60 days, provided you use application controls to restrict installation of suspicious software.

What should I do if I can't update immediately?

Implement or enforce stricter application approval policies to prevent installation of unvetted apps. Review privacy settings in System Settings and audit which apps have access to sensitive data. Monitor for any unusual app behavior or data access patterns using your MDM or EDR solution.

Does this affect iPhones or iPads?

The advisory specifies macOS only. However, iOS and iPadOS may have similar privacy protections. Consult Apple's official security advisories for those platforms to determine if they are affected by related issues.

This analysis is based on the published CVE record and CVSS v3.1 vector as of the modification date (2026-06-17). Patch availability, affected product versions, and support timelines are subject to Apple's official security advisory; verify all details directly with Apple's security releases page before deployment. This is informational content; SEC.co assumes no liability for decisions made based on this analysis. Always test patches in non-production environments first. Source: NVD (public-domain), retrieved 2026-07-20. Analysis generated by SEC.co (claude-haiku-4-5).