vulnerability
OS X update for Shortcuts (CVE-2025-30465)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 10 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | Apr 1, 2025 | Apr 1, 2025 | Apr 6, 2026 |
Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Apr 1, 2025
Added
Apr 1, 2025
Modified
Apr 6, 2026
Description
A permissions issue was addressed with improved validation. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sequoia 15.7.2, macOS Sonoma 14.7.5, macOS Sonoma 14.8.2, macOS Tahoe 26.1, macOS Ventura 13.7.5. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.
Solutions
apple-osx-upgrade-13_7_5apple-osx-upgrade-14_7_5apple-osx-upgrade-14_8_2apple-osx-upgrade-15_4apple-osx-upgrade-15_7_2apple-osx-upgrade-26_1
References
- CVE-2025-30465
- https://attackerkb.com/topics/CVE-2025-30465
- CWE-276
- EUVD-EUVD-2025-8901
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-8901
- https://support.apple.com/en-us/122373
- https://support.apple.com/en-us/122374
- https://support.apple.com/en-us/122375
- https://support.apple.com/en-us/125634
- https://support.apple.com/en-us/125635
- https://support.apple.com/en-us/125636
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.