CVE Feed

    Dashboard / CVE / CVE-2025-65843

    CVE-2025-65843

    Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generation feature. The application follows symbolic links placed inside the ~/Library/Logs/Aquarius directory and treats them as regular files. When building the support ZIP, Aquarius recursively enumerates logs using a JUCE directory iterator configured to follow symlinks, and later writes file data without validating whether the target is a symbolic link. A local attacker can exploit this behavior by planting symlinks to arbitrary filesystem locations, resulting in unauthorized disclosure or modification of arbitrary files. When chained with the associated HelperTool privilege escalation issue, root-owned files may also be exposed.

    Published:Dec 3, 2025
    Last Modified:Dec 18, 2025
    EPS:Dec 3, 2025
    EPSS Score:0.00024
    CVSS Score:7.7

    Affected Products

    Vendor
    Acustica-audio
    Product
    Aquarius
    Vendor
    Acusticaudio
    Product
    Aquarius Desktop
    Vendor
    Apple
    Product
    Macos

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High