← All CVEs

CVE-2025-30433

critical · 9.8

This issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.

9.8
CVSS
1.2%
EPSS (exploit prob.)
68th
EPSS percentile
2025-03-31
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-284

Affected products

VendorProductAffected versions
appleipados< 17.7.6
appleipados>= 18.0, < 18.4
appleiphone_os< 18.4
applemacos>= 13.0, < 13.7.5
applemacos>= 14.0, < 14.7.5
applemacos>= 15.0, < 15.4
applevisionos< 2.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-30433