A critical vulnerability in macOS, identified as CVE-2025-43530, allows attackers to bypass the Transparency, Consent, and Control (TCC) framework, which is designed to protect sensitive user data such as microphone, camera, and document access. The flaw is exploited through the VoiceOver screen reader framework and the com.apple.scrod service, both of which possess elevated system permissions. Attackers can leverage this vulnerability to execute arbitrary AppleScript commands and send AppleEvents to any application, including Finder, thereby circumventing TCC security controls without requiring administrative privileges.
The attack can be carried out in two primary ways: by injecting malicious code into Apple-signed system binaries, exploiting the system's failure to properly distinguish between legitimate and compromised processes, and by performing a Time-of-Check-Time-of-Use (TOCTOU) attack to manipulate applications between security verification and execution. Successful exploitation grants attackers the ability to access sensitive documents, control the microphone, and execute code without user consent, effectively nullifying TCC protections on affected macOS systems.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers publicly disclosed CVE-2025-43530, a macOS Transparency, Consent, and Control bypass involving VoiceOver and the com.apple.scrod service that can allow arbitrary AppleScript execution and access to sensitive data without user consent. Reports also noted that a working proof-of-concept exploit was publicly available, increasing the risk of abuse.
Apple addressed CVE-2025-43530 in macOS 26.2 by strengthening validation around trusted services with a more robust entitlement-based check. Users and organizations were advised to update to macOS 26.2 or later to mitigate the issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcesecurityonline.info
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.