CVE-2025-43449: Infoleak
Published Nov 3, 2025
·Updated
Accessibility. A permissions issue was addressed with additional restrictions.
Credit
Zhongcheng Li(IES Red Team of ByteDance), Ron Masas(BreakPoint), Pinak Oza, an anonymous researcher, Rosyna Keller(Totally Not Malicious Software), Gergely Kalman@@gergely_kalman, JZ, Duy Trần@@khanhduytran0, Dennis Briner, Hikerell (Loadshine Lab), Wojciech Regula(SecuRing), Kirin@@Pwnrin(Fudan University), LFY@@secsys(Fudan University), Lukaah Marlowe, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), pattern-f@@pattern_F_, iisBuri, Cristian Dinca (icmd.tech), Apple, Dave G.(supernetworks), Alex Radocea(supernetworks), Taavi Eomäe(Zone Media), Romain Lebesle(Khatima), Himanshu Bharti@@Xpl0itme(Khatima), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Google Threat Analysis Group, Kirin@@Pwnrin, Asaf Cohen, KPC(Cisco Talos), @@RenwaX23, Stanislav Jelezoglo, Joshua Thomas, Dalibor Milanovic, Isaiah Wan, Will Caine, Thomas Salomon, Sufiyan Gouri (TU Darmstadt), Phil Scott & Richard Hyunho Im (@richeeta)@@MrPeriPeri, Mark Bowers, Joey Hewitt, Dylan Rollins, Arthur Baudoin, Andr.Ess, Mikael Kinnman, Aleksejs Popovs, Phil Beauvoir, Google Big Sleep, Gary Kwong, rheza@@ginggilBesel, Justin Cohen(Google), Nan Wang@@eternalsakura13, rheza@@ginggilBesel(Trend Micro Zero Day Initiative), shandikri(Trend Micro Zero Day Initiative), Gary Kwong(Trend Micro Zero Day Initiative), Lehan Dilusha Jayasinghe, Tom Van Goethem
Affected Software
4 affected componentsFixes available
Apple iOS<26.1
26.1
Apple iPadOS<26.1
26.1
Apple iPadOS<26.1
Apple iPhone OS<26.1
Event History
Nov 3, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Nov 4, 2025
CVE Published
via MITRE·01:15 AM
Data Sourced
via MITRE·01:15 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43449?
CVE-2025-43449 has been classified with a severity rating that indicates it poses significant security risks due to various privacy and permissions issues.
2
How do I fix CVE-2025-43449?
To fix CVE-2025-43449, users should update their devices to the latest versions of iOS, iPadOS, or Apple iPhone OS that are beyond version 26.1.
3
What types of devices are affected by CVE-2025-43449?
CVE-2025-43449 affects devices running Apple iOS, Apple iPadOS, and Apple iPhone OS up to version 26.1.
4
What issues does CVE-2025-43449 address?
CVE-2025-43449 addresses issues related to permissions, privacy, memory handling, and cache management.
5
Who is the vendor responsible for addressing CVE-2025-43449?
The vendor responsible for addressing CVE-2025-43449 is Apple.