CVE-2025-43437: Input Validation
Accessibility. A permissions issue was addressed with additional restrictions.
Other sources
An information disclosure issue was addressed with improved privacy controls. This issue is fixed in iOS 26.1 and iPadOS 26.1. An app may be able to fingerprint the user.
— MITRE
Apple Account. A privacy issue was addressed with improved checks.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Apple TV Remote. The issue was addressed with improved handling of caches.
— Apple
AppleMobileFileIntegrity. This issue was addressed with improved validation of symlinks.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43442
- CVE-2025-43455
- CVE-2025-43447
- CVE-2025-43462
- CVE-2025-43449
- CVE-2025-43379
- CVE-2025-43407
- CVE-2025-43423
- CVE-2025-43450
- CVE-2025-43448
- CVE-2025-43426
- CVE-2025-43350
- CVE-2025-43436
- CVE-2025-43445
- CVE-2025-43498
- CVE-2025-43507
- CVE-2025-43444
- CVE-2025-43398
- CVE-2025-43510
- CVE-2025-43520
- CVE-2025-43413
- CVE-2025-43494
- CVE-2025-43496
- CVE-2025-43294
- CVE-2025-43437
- CVE-2025-43386
- CVE-2025-43385
- CVE-2025-43384
- CVE-2025-43383
- CVE-2025-43424
- CVE-2025-43389
- CVE-2025-43439
- CVE-2025-43391
- CVE-2025-46316
- CVE-2025-43493
- CVE-2025-43503
- CVE-2025-43502
- CVE-2025-43500
- CVE-2025-43454
- CVE-2025-43418
- CVE-2025-43460
- CVE-2025-43422
- CVE-2025-43452
- CVE-2025-43480
- CVE-2025-43458
- CVE-2025-43430
- CVE-2025-43427
- CVE-2025-43443
- CVE-2025-43441
- CVE-2025-43435
- CVE-2025-43425
- CVE-2025-43440
- CVE-2025-43438
- CVE-2025-43457
- CVE-2025-43434
- CVE-2025-43495
- CVE-2025-43433
- CVE-2025-43431
- CVE-2025-43432
- CVE-2025-43429
- CVE-2025-43421
- CVE-2025-43392
Frequently Asked Questions
What is the severity of CVE-2025-43437?
CVE-2025-43437 is considered a moderate severity vulnerability due to potential information disclosure risks.
How do I fix CVE-2025-43437?
To fix CVE-2025-43437, update your device to iOS 26.1 or iPadOS 26.1.
What kind of information might be disclosed in CVE-2025-43437?
CVE-2025-43437 may allow an app to fingerprint the user, potentially revealing sensitive user information.
Which devices are affected by CVE-2025-43437?
CVE-2025-43437 affects Apple iOS devices and iPadOS devices running versions prior to 26.1.
Was CVE-2025-43437 resolved in software updates?
Yes, CVE-2025-43437 was resolved in the software updates for iOS 26.1 and iPadOS 26.1.