Privacy Issue in Apple Products Affecting User Data Security
CVE-2025-43507

6.5MEDIUM

Key Information:

Vendor

Apple

Vendor
CVE Published:
4 November 2025

What is CVE-2025-43507?

A privacy concern has been uncovered in various Apple operating systems, where sensitive user data may inadvertently be exposed, allowing applications to potentially fingerprint users. This issue highlights a security loophole that affects the confidentiality of user information on devices running iOS, iPadOS, watchOS, and visionOS prior to version 26.1. Apple has addressed this vulnerability in their latest updates, ensuring improved data privacy for users.

Affected Version(s)

iOS and iPadOS < 26.1

visionOS < 26.1

watchOS < 26.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.