Permissions Issue in Apple Ecosystem Products
CVE-2025-43436

7.5HIGH

Key Information:

Vendor

Apple

Vendor
CVE Published:
4 November 2025

What is CVE-2025-43436?

A vulnerabilities relating to permissions management within Apple's ecosystem have been addressed with the introduction of stringent restrictions. These updates, applicable across various platforms including watchOS, iOS, iPadOS, tvOS, and visionOS, effectively mitigate the risk of unauthorized app enumeration, thus enhancing user data privacy and security. Users are encouraged to update their devices to the latest versions to ensure the protection of installed applications.

Affected Version(s)

iOS and iPadOS < 26.1

tvOS < 26.1

visionOS < 26.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.