CVE-2025-43379
Published Nov 3, 2025
·Updated
Accessibility. A permissions issue was addressed with additional restrictions.
Credit
Mickey Jin@@patch1t, Gergely Kalman@@gergely_kalman, Joseph Ravichandran@@0xjprx(MIT CSAIL), Dave G. (supernetworks.org), JZ, Zhongcheng Li(IES Red Team of ByteDance), Michael Reeves@@IntegralPilot, Morris Richman@@morrisinlife, Csaba Fitzl@@theevilbit(Kandji), Hikerell (Loadshine Lab), 이동하 (Lee Dong Ha(BoB 14th), wac(Trend Micro Zero Day Initiative), an anonymous researcher, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Rodolphe BRUNETTI@@eisw0lf(Lupus Nova), pattern-f@@pattern_F_, Ferdous Saljooki@@malwarezoo(Jamf), Murray Mike, 이동하 (Lee Dong Ha)(SSA Lab), Cristian Dinca (icmd.tech), Apple, Dave G.(supernetworks), Alex Radocea(supernetworks), Taavi Eomäe(Zone Media), Kirin@@Pwnrin, Atul R V, Asaf Cohen, CVE-2024-43398, CVE-2024-49761, CVE-2025-6442, Vivek Dhar, ASI (RM) in Border Security Force, FTR HQ BSF Kashmir, Nikolai Skliarenko(Trend Micro Zero Day Initiative), Jonathan Bar Or@@yo_yo_yo_jbo(Microsoft), Alexia Wilson(Microsoft), Christine Fossaceca(Microsoft), Wang Yu(Cyberserval), Ryan Dowd@@_rdowd, Ron Masas(BreakPoint), Pinak Oza, iisBuri, Romain Lebesle(Khatima), Himanshu Bharti@@Xpl0itme(Khatima), Dalibor Milanovic, @@RenwaX23, Stanislav Jelezoglo, Aleksejs Popovs, Phil Beauvoir, Google Big Sleep, Nan Wang@@eternalsakura13, rheza@@ginggilBesel(Trend Micro Zero Day Initiative), shandikri(Trend Micro Zero Day Initiative), Gary Kwong(Trend Micro Zero Day Initiative), Justin Cohen(Google), Tom Van Goethem, Nolan Astrein(Kandji), Duy Trần@@khanhduytran0, Adwiteeya Agrawal, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), BynarIO AI (bynar.io), Kirin@@Pwnrin(Microsoft), Gary Kwong, rheza@@ginggilBesel, Wojciech Regula(SecuRing), Kirin@@Pwnrin(Fudan University), LFY@@secsys(Fudan University), Kenneth Chew, @@EthanArbuckle, Google Threat Analysis Group, Doug Hogan, KPC(Cisco Talos), Zhongquan Li@@Guluisacat, an anonymous researcher(Microsoft), Amy@@asentientbot, CVE-2025-32462, CVE-2025-53906, @@cloudlldb, Dennis Briner, Lukaah Marlowe, Rosyna Keller(Totally Not Malicious Software), Joshua Thomas, Isaiah Wan, Will Caine, Thomas Salomon, Sufiyan Gouri (TU Darmstadt), Phil Scott & Richard Hyunho Im (@richeeta)@@MrPeriPeri, Mark Bowers, Joey Hewitt, Dylan Rollins, Arthur Baudoin, Andr.Ess, Mikael Kinnman, Lehan Dilusha Jayasinghe
Affected Software
15 affected componentsFixes available
Apple WatchOS<26.1
26.1
Apple tvOS<26.1
26.1
Apple visionOS<26.1
26.1
Apple macOS Tahoe<26.1
26.1
Apple macOS Sequoia<15.7.2
15.7.2
Apple macOS Sonoma<14.8.2
14.8.2
Apple iOS<26.1
26.1
Apple iPadOS<26.1
26.1
Apple iPadOS<26.1
Apple iPhone OS<26.1
Apple macOS<14.8.2
Apple macOS>=15.0<15.7.2
Apple tvOS<26.1
Apple visionOS<26.1
Apple WatchOS<26.1
Event History
Nov 3, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
WeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionAffected Software
Updated
via Apple·12:00 AM
Affected Software
Nov 4, 2025
CVE Published
via MITRE·01:17 AM
Data Sourced
via MITRE·01:17 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43379?
The severity of CVE-2025-43379 is considered critical due to the potential for unauthorized access to sensitive information.
2
How do I fix CVE-2025-43379?
To fix CVE-2025-43379, update your affected Apple devices to the latest version specified in Apple's advisory.
3
What products are affected by CVE-2025-43379?
CVE-2025-43379 affects Apple devices including watchOS, tvOS, visionOS, macOS Tahoe, macOS Sequoia, macOS Sonoma, iOS, and iPadOS.
4
Can CVE-2025-43379 affect my privacy?
Yes, CVE-2025-43379 includes a privacy issue that could potentially expose personal data.
5
What types of issues does CVE-2025-43379 address?
CVE-2025-43379 addresses permissions and privacy issues along with logical vulnerabilities in the Admin Framework.