CVE-2025-30465

critical

Description

A permissions issue was addressed with improved validation. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sequoia 15.7.2, macOS Sonoma 14.7.5, macOS Sonoma 14.8.2, macOS Tahoe 26.1, macOS Ventura 13.7.5. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.

References

https://support.apple.com/en-us/125636

https://support.apple.com/en-us/125635

https://support.apple.com/en-us/125634

https://support.apple.com/en-us/122375

https://support.apple.com/en-us/122374

https://support.apple.com/en-us/122373

https://support.apple.com/en-us/122372

http://seclists.org/fulldisclosure/2025/Apr/9

http://seclists.org/fulldisclosure/2025/Apr/8

http://seclists.org/fulldisclosure/2025/Apr/5

http://seclists.org/fulldisclosure/2025/Apr/10

Details

Source: Mitre, NVD

Published: 2025-03-31

Updated: 2026-04-02

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00014