CVE-2025-43309: Input Validation
A logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An attacker with physical access to an iOS device may be able to view notification contents from the Lock Screen.
Other sources
Apple Neural Engine. An out-of-bounds access issue was addressed with improved bounds checking.
— Apple
AppleMobileFileIntegrity. A permissions issue was addressed with additional restrictions.
— Apple
Audio. An out-of-bounds access issue was addressed with improved bounds checking.
— Apple
Audio. An out-of-bounds read was addressed with improved bounds checking.
— Apple
Authentication Services. The issue was addressed with improved UI.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43344
- CVE-2025-43317
- CVE-2025-43346
- CVE-2025-43361
- CVE-2025-43360
- CVE-2025-43354
- CVE-2025-43303
- CVE-2025-43357
- CVE-2025-43323
- CVE-2025-43349
- CVE-2025-43372
- CVE-2025-43338
- CVE-2025-43302
- CVE-2025-31255
- CVE-2025-43359
- CVE-2025-43345
- CVE-2025-43362
- CVE-2025-43365
- CVE-2025-43355
- CVE-2025-43203
- CVE-2025-43309
- CVE-2025-46306
- CVE-2025-31254
- CVE-2025-43329
- CVE-2025-43358
- CVE-2025-30468
- CVE-2025-43190
- CVE-2025-6965
- CVE-2025-43347
- CVE-2025-43356
- CVE-2025-43272
- CVE-2025-43343
- CVE-2025-43342
- CVE-2025-43419
- CVE-2025-43376
- CVE-2025-43368
Frequently Asked Questions
What is the severity of CVE-2025-43309?
CVE-2025-43309 is considered a moderate severity vulnerability due to the potential for unauthorized access to sensitive notification information.
How do I fix CVE-2025-43309?
To mitigate CVE-2025-43309, update your Apple iOS or iPadOS device to version 26 or later.
Who is affected by CVE-2025-43309?
CVE-2025-43309 affects any user with physical access to an iOS or iPadOS device running version before 26.
What type of vulnerability is CVE-2025-43309?
CVE-2025-43309 is classified as a logic issue that allows accessed notification contents on the Lock Screen.
What conditions are necessary for exploiting CVE-2025-43309?
Exploitation of CVE-2025-43309 requires physical access to the affected iOS or iPadOS device.