CVE-2025-5469: Dylib Hijacking in Yandex Messenger
Published Dec 9, 2025
·Updated
Uncontrolled Search Path Element vulnerability in Yandex Messenger on MacOS allows Search Order Hijacking.This issue affects Telemost: before 2.245
Affected Software
1 affected component
Yandex Messenger<2.245
Event History
Dec 9, 2025
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-5469?
CVE-2025-5469 is classified as a medium severity vulnerability due to its potential for search order hijacking in Yandex Messenger.
2
How do I fix CVE-2025-5469?
To fix CVE-2025-5469, upgrade Yandex Messenger to version 2.245 or later.
3
What systems are affected by CVE-2025-5469?
CVE-2025-5469 affects Yandex Messenger on macOS, specifically versions prior to 2.245.
4
What exploitation method is used in CVE-2025-5469?
CVE-2025-5469 can be exploited through uncontrolled search path elements leading to search order hijacking.
5
Is CVE-2025-5469 a remote or local vulnerability?
CVE-2025-5469 is primarily considered a local vulnerability as it requires access to execute malicious code on the affected system.