CVE-2025-43459: Input Validation
An authentication issue was addressed with improved state management. This issue is fixed in watchOS 26.1. An attacker with physical access to a locked Apple Watch may be able to view Live Voicemail.
Other sources
Apple Account. A privacy issue was addressed with improved checks.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. This issue was addressed with improved validation of symlinks.
— Apple
CloudKit. This issue was addressed with improved validation of symlinks.
— Apple
CoreServices. A permissions issue was addressed with additional restrictions.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43455
- CVE-2025-43447
- CVE-2025-43462
- CVE-2025-43379
- CVE-2025-43448
- CVE-2025-43436
- CVE-2025-43445
- CVE-2025-43507
- CVE-2025-43400
- CVE-2025-43444
- CVE-2025-43398
- CVE-2025-43510
- CVE-2025-43520
- CVE-2025-43413
- CVE-2025-43494
- CVE-2025-43496
- CVE-2025-43294
- CVE-2025-43459
- CVE-2025-43503
- CVE-2025-43500
- CVE-2025-43480
- CVE-2025-43458
- CVE-2025-43430
- CVE-2025-43443
- CVE-2025-43440
- CVE-2025-43438
- CVE-2025-43457
- CVE-2025-43434
- CVE-2025-43435
- CVE-2025-43425
- CVE-2025-43433
- CVE-2025-43431
- CVE-2025-43432
- CVE-2025-43429
- CVE-2025-43392
Frequently Asked Questions
What is the severity of CVE-2025-43459?
CVE-2025-43459 is classified as a significant authentication issue that could lead to unauthorized access to sensitive information on locked Apple Watches.
How do I fix CVE-2025-43459?
To mitigate CVE-2025-43459, update your Apple Watch to watchOS version 26.1 or later.
Who is affected by CVE-2025-43459?
Users of Apple Watch running watchOS versions earlier than 26.1 are affected by CVE-2025-43459.
What kind of access does CVE-2025-43459 allow?
CVE-2025-43459 may allow an attacker with physical access to view Live Voicemail on a locked Apple Watch.
What improvements are made in the fix for CVE-2025-43459?
The fix for CVE-2025-43459 includes improved state management and enhanced privacy checks.