CVE-2025-30465: Critical Vulnerability in Apple macOS and iPadOS – Shortcut Permissions Issue
A critical vulnerability has been discovered in Apple’s macOS and iPadOS, tracked as CVE-2025-30465. This issue arises when a shortcut is able to access files that are normally restricted to the Shortcuts app. The flaw affects macOS versions prior to 15.4 and iPadOS versions before 17.7, and has been fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, and macOS Sonoma 14.7.5.
Details of the Vulnerability
The vulnerability is caused by a permissions issue, allowing an app to bypass the normal restrictions in place within the Shortcuts app. This could potentially enable an attacker to access files that would otherwise be inaccessible, risking the exposure of sensitive data.
Apple addressed this issue by implementing improved validation of shortcut permissions. These changes ensure that only authorized shortcuts can access the system’s restricted areas, thus mitigating the risk of unauthorized access.
CVSS Score and Impact
The CVSS v3.1 score for this vulnerability is 9.8, indicating a critical level of risk. The attack vector is remote, with low complexity required for exploitation. No user interaction is needed, and no special privileges are required for an attacker to exploit the vulnerability.
The potential impacts are significant, as the attacker could:
- Access sensitive data – High confidentiality impact.
- Alter system data – High integrity impact.
- Disrupt system availability – High availability impact.
Mitigation
Apple has resolved this issue by adding additional restrictions to the Shortcuts app and updating the affected systems. Users are strongly encouraged to update to macOS Ventura 13.7.5, iPadOS 17.7.6, or later versions to protect their systems from this critical flaw.
Conclusion
The CVE-2025-30465 vulnerability highlights the importance of proper permissions and sandboxing in preventing unauthorized access to protected system resources. macOS and iPadOS users should update their devices immediately to safeguard sensitive information and prevent exploitation.