CVE-2025-43439: Input Validation
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, visionOS 26.1. An app may be able to fingerprint the user.
Other sources
Accessibility. A permissions issue was addressed with additional restrictions.
— Apple
Apple Account. A privacy issue was addressed with improved checks.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Apple TV Remote. The issue was addressed with improved handling of caches.
— Apple
AppleMobileFileIntegrity. This issue was addressed with improved validation of symlinks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43442
- CVE-2025-43444
- CVE-2025-43423
- CVE-2025-43450
- CVE-2025-43448
- CVE-2025-43445
- CVE-2025-43507
- CVE-2025-43398
- CVE-2025-43510
- CVE-2025-43520
- CVE-2025-43496
- CVE-2025-43494
- CVE-2025-43365
- CVE-2025-43386
- CVE-2025-43383
- CVE-2025-43385
- CVE-2025-43384
- CVE-2025-43377
- CVE-2025-43389
- CVE-2025-43439
- CVE-2025-43493
- CVE-2025-43503
- CVE-2025-43499
- CVE-2025-43454
- CVE-2025-43399
- CVE-2025-43418
- CVE-2025-43438
- CVE-2025-43434
- CVE-2025-43458
- CVE-2025-43433
- CVE-2025-43431
- CVE-2025-43441
- CVE-2025-43435
- CVE-2025-43429
- CVE-2025-43443
- CVE-2025-43495
- CVE-2025-43392
- CVE-2025-43511
- CVE-2025-43455
- CVE-2025-43447
- CVE-2025-43462
- CVE-2025-43379
- CVE-2025-43407
- CVE-2025-43436
- CVE-2025-43498
- CVE-2025-43413
- CVE-2025-43502
- CVE-2025-43500
- CVE-2025-43480
- CVE-2025-43430
- CVE-2025-43427
- CVE-2025-43425
- CVE-2025-43440
- CVE-2025-43457
- CVE-2025-43432
- CVE-2025-43421
- CVE-2025-43449
- CVE-2025-43426
- CVE-2025-43350
- CVE-2025-43294
- CVE-2025-43437
- CVE-2025-43424
- CVE-2025-43391
- CVE-2025-46316
- CVE-2025-43460
- CVE-2025-43422
- CVE-2025-43452
Frequently Asked Questions
What is the severity of CVE-2025-43439?
CVE-2025-43439 is a high-severity privacy issue that could allow apps to fingerprint users.
How do I fix CVE-2025-43439?
To fix CVE-2025-43439, update your device to iOS 26.1, iPadOS 26.1, or visionOS 26.1.
What types of devices are affected by CVE-2025-43439?
CVE-2025-43439 affects Apple devices running iOS, iPadOS, and visionOS prior to version 26.1.
What is the impact of CVE-2025-43439 on user privacy?
CVE-2025-43439 could potentially allow applications to collect sensitive user information without consent.
Was there a permissions issue related to CVE-2025-43439?
Yes, CVE-2025-43439 included a permissions issue that was addressed with additional restrictions in the latest update.