CVE-2025-5470: Yandex Disk
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Uncontrolled Search Path Element vulnerability in Yandex Disk on MacOS allows Search Order Hijacking.This issue affects Disk: before 3.2.45.3275.
Affected products
- Yandex Disk: before 3.2.45.3275 (fixed in 3.2.45.3275)
Published 2025-12-09. Last modified 2026-10-07.