CVE-2025-43379: Medium severity Apple WatchOS vulnerability
Accessibility. A permissions issue was addressed with additional restrictions.
Other sources
Admin Framework. A logic issue was addressed with improved checks.
— Apple
Admin Framework. The issue was addressed with improved checks.
— Apple
App Store. A logging issue was addressed with improved data redaction.
— Apple
Apple Account. A privacy issue was addressed with improved checks.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.7.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.8.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iOS 26.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iPadOS 26.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in macOS Sequoia 15.7.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in macOS Sonoma 14.8.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in macOS Tahoe 26.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in tvOS 26.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in visionOS 26.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in watchOS 26.1 - Configuration
Update to include the improved path/symlink validation so directory-path handling and symlink traversal are validated safely (this is described as being addressed with improved validation of symlinks and improved path validation).
Apple platform (handling of directory paths) symlink validation = improved validation of symlinks
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43455
- CVE-2025-43447
- CVE-2025-43462
- CVE-2025-43379
- CVE-2025-43448
- CVE-2025-43436
- CVE-2025-43445
- CVE-2025-43507
- CVE-2025-43400
- CVE-2025-43444
- CVE-2025-43398
- CVE-2025-43510
- CVE-2025-43520
- CVE-2025-43413
- CVE-2025-43494
- CVE-2025-43496
- CVE-2025-43294
- CVE-2025-43459
- CVE-2025-43503
- CVE-2025-43500
- CVE-2025-43480
- CVE-2025-43458
- CVE-2025-43430
- CVE-2025-43443
- CVE-2025-43440
- CVE-2025-43438
- CVE-2025-43457
- CVE-2025-43434
- CVE-2025-43435
- CVE-2025-43425
- CVE-2025-43433
- CVE-2025-43431
- CVE-2025-43432
- CVE-2025-43429
- CVE-2025-43392
- CVE-2025-43322
- CVE-2025-43337
- CVE-2025-43390
- CVE-2025-43468
- CVE-2025-43469
- CVE-2025-43378
- CVE-2025-43478
- CVE-2025-43407
- CVE-2025-43446
- CVE-2025-43361
- CVE-2025-43423
- CVE-2025-43472
- CVE-2025-43394
- CVE-2025-43395
- CVE-2025-43401
- CVE-2025-43292
- CVE-2025-43479
- CVE-2025-43382
- CVE-2025-43481
- CVE-2025-43387
- CVE-2025-43420
- CVE-2025-43498
- CVE-2025-43348
- CVE-2025-43474
- CVE-2025-43396
- CVE-2025-43383
- CVE-2025-43385
- CVE-2025-43384
- CVE-2025-43377
- CVE-2025-43389
- CVE-2025-43410
- CVE-2025-43411
- CVE-2025-43405
- CVE-2025-43391
- CVE-2024-43398
- CVE-2024-49761
- CVE-2025-6442
- CVE-2025-43335
- CVE-2025-43408
- CVE-2025-43476
- CVE-2025-30465
- CVE-2025-43414
- CVE-2025-43499
- CVE-2025-43380
- CVE-2025-43477
- CVE-2025-43399
- CVE-2025-43336
- CVE-2025-43397
- CVE-2025-43409
- CVE-2025-43334
- CVE-2025-43412
- CVE-2025-43373
- CVE-2025-43386
- CVE-2025-43439
- CVE-2025-43493
- CVE-2025-43502
- CVE-2025-43427
- CVE-2025-43441
- CVE-2025-43421
- CVE-2025-43442
- CVE-2025-43449
- CVE-2025-43450
- CVE-2025-43426
- CVE-2025-43350
- CVE-2025-43437
- CVE-2025-43424
- CVE-2025-46316
- CVE-2025-43454
- CVE-2025-43418
- CVE-2025-43460
- CVE-2025-43422
- CVE-2025-43452
- CVE-2025-43495
- CVE-2025-43372
- CVE-2025-43338
- CVE-2025-31199
- CVE-2025-6965
- CVE-2025-43471
- CVE-2025-46313
- CVE-2025-43388
- CVE-2025-43466
- CVE-2025-43465
- CVE-2025-43497
- CVE-2025-43461
- CVE-2025-43381
- CVE-2025-43470
- CVE-2025-46315
- CVE-2025-43464
- CVE-2025-43467
- CVE-2025-43364
- CVE-2025-43506
- CVE-2025-43508
- CVE-2025-43393
- CVE-2025-43406
- CVE-2025-43404
- CVE-2025-43339
- CVE-2025-43473
- CVE-2025-43351
- CVE-2025-43463
- CVE-2025-32462
- CVE-2025-53906
- CVE-2025-43402
Frequently Asked Questions
What is the severity of CVE-2025-43379?
The severity of CVE-2025-43379 is considered critical due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2025-43379?
To fix CVE-2025-43379, update your affected Apple devices to the latest version specified in Apple's advisory.
What products are affected by CVE-2025-43379?
CVE-2025-43379 affects Apple devices including watchOS, tvOS, visionOS, macOS Tahoe, macOS Sequoia, macOS Sonoma, iOS, and iPadOS.
Can CVE-2025-43379 affect my privacy?
Yes, CVE-2025-43379 includes a privacy issue that could potentially expose personal data.
What types of issues does CVE-2025-43379 address?
CVE-2025-43379 addresses permissions and privacy issues along with logical vulnerabilities in the Admin Framework.