macOS TCC Bypass Vulnerability via VoiceOver Exploitation (CVE-2025-43530)
A critical vulnerability in macOS, identified as CVE-2025-43530, allows attackers to bypass the Transparency, Consent, and Control (TCC) framework, which is designed to protect sensitive user data such as microphone, camera, and document access. The flaw is exploited through the VoiceOver screen reader framework and the com.apple.scrod service, both of which possess elevated system permissions. Attackers can leverage this vulnerability to execute arbitrary AppleScript commands and send AppleEvents to any application, including Finder, thereby circumventing TCC security controls without requiring administrative privileges.
The attack can be carried out in two primary ways: by injecting malicious code into Apple-signed system binaries, exploiting the system's failure to properly distinguish between legitimate and compromised processes, and by performing a Time-of-Check-Time-of-Use (TOCTOU) attack to manipulate applications between security verification and execution. Successful exploitation grants attackers the ability to access sensitive documents, control the microphone, and execute code without user consent, effectively nullifying TCC protections on affected macOS systems.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
2 events from the most recent confirmed update back to the earliest known activity.
Public disclosure of CVE-2025-43530 TCC bypass and PoC
Researchers publicly disclosed CVE-2025-43530, a macOS Transparency, Consent, and Control bypass involving VoiceOver and the com.apple.scrod service that can allow arbitrary AppleScript execution and access to sensitive data without user consent. Reports also noted that a working proof-of-concept exploit was publicly available, increasing the risk of abuse.
Apple fixes macOS TCC bypass in macOS 26.2
Apple addressed CVE-2025-43530 in macOS 26.2 by strengthening validation around trusted services with a more robust entitlement-based check. Users and organizations were advised to update to macOS 26.2 or later to mitigate the issue.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
Critical macOS Flaw Lets Attackers Bypass Apple Privacy Controls Without Consent
techrepublic.com
Open sourceNew TCC Bypass (CVE-2025-43530) Exposes macOS to Unchecked Automation
securityonline.info
Open sourceNew macOS TCC Bypass Vulnerability Allow Attackers to Access Sensitive User Data
cybersecuritynews.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


