Authentication Vulnerability in Apple Watch - Apple Inc.
CVE-2025-43459

4.6MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
4 November 2025

What is CVE-2025-43459?

An authentication vulnerability exists in the Apple Watch that could allow an attacker with physical access to a locked device to potentially view Live Voicemail messages. This issue has been addressed in watchOS 26.1, enhancing the state management protocols to prevent unauthorized access. Users are encouraged to update their devices to safeguard against this security risk.

Affected Version(s)

watchOS < 26.1

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.