CVE-2025-43360: Infoleak
Published Sep 15, 2025
·Updated
Apple Neural Engine. An out-of-bounds access issue was addressed with improved bounds checking.
Credit
Mickey Jin@@patch1t, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Michael Reeves@@IntegralPilot, Nikita Sakalouski, Csaba Fitzl@@theevilbit(Kandji), Rosyna Keller(Totally Not Malicious Software), Guilherme Rambo(Best Buddy Apps), Yinyi Wu@@_3ndy1(Dawn Security Lab of JD), @@zlluny(Trend Micro Zero Day Initiative), 이동하 (Lee Dong Ha)(SSA Lab), Keisuke Hosoda, Viktor Oreshkin, Philipp Baldauf, Minghao Lin@@Y1nKoc, Lyutoon@@Lyutoon_, YingQi Shi@@Mas0n, Dawuge(Shuffle Team), Tom Brzezinski, Abhay Kailasia@@abhay_kailasia(C), KPC(Cisco Talos), Evan Waelde, an anonymous researcher, 정답이 아닌 해답, Richard Hyunho Im@@richeeta, Noah Gregory (wts.dev), CVE-2025-6965, JZ, Seo Hyun-gyu@@wh1te4ever, Luke Roberts@@rookuu, Jaydev Ahire, Big Bear, Ignacio Sanmillan@@ulexec, Mike Cardwell(grepular), Bob Lord, Pawel Wylecial(REDTEAM)
Affected Software
6 affected componentsFixes available
Apple iOS<26
Apple iPadOS<26
Apple iPadOS<26.0
Apple iPhone OS<26.0
Apple iOS<26
26
Apple iPadOS<26
26
Event History
Sep 15, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Nov 4, 2025
CVE Published
via MITRE·01:16 AM
Data Sourced
via MITRE·01:16 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43360?
CVE-2025-43360 is rated as a moderate severity vulnerability that can lead to unintended exposure of password fields.
2
How do I fix CVE-2025-43360?
To fix CVE-2025-43360, update to iOS 26 or iPadOS 26, where the issue has been addressed.
3
What is CVE-2025-43360 about?
CVE-2025-43360 involves a vulnerability in Apple iOS and iPadOS where password fields may be unintentionally revealed.
4
Which software versions are affected by CVE-2025-43360?
CVE-2025-43360 affects versions of iOS and iPadOS earlier than 26.
5
Is there a workaround for CVE-2025-43360?
There are no known workarounds for CVE-2025-43360; updating to the latest software version is the recommended solution.