CVE-2025-43460: Input Validation
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.
Other sources
Accessibility. A permissions issue was addressed with additional restrictions.
— Apple
Apple Account. A privacy issue was addressed with improved checks.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Apple TV Remote. The issue was addressed with improved handling of caches.
— Apple
AppleMobileFileIntegrity. This issue was addressed with improved validation of symlinks.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43442
- CVE-2025-43455
- CVE-2025-43447
- CVE-2025-43462
- CVE-2025-43449
- CVE-2025-43379
- CVE-2025-43407
- CVE-2025-43423
- CVE-2025-43450
- CVE-2025-43448
- CVE-2025-43426
- CVE-2025-43350
- CVE-2025-43436
- CVE-2025-43445
- CVE-2025-43498
- CVE-2025-43507
- CVE-2025-43444
- CVE-2025-43398
- CVE-2025-43510
- CVE-2025-43520
- CVE-2025-43413
- CVE-2025-43494
- CVE-2025-43496
- CVE-2025-43294
- CVE-2025-43437
- CVE-2025-43386
- CVE-2025-43385
- CVE-2025-43384
- CVE-2025-43383
- CVE-2025-43424
- CVE-2025-43389
- CVE-2025-43439
- CVE-2025-43391
- CVE-2025-46316
- CVE-2025-43493
- CVE-2025-43503
- CVE-2025-43502
- CVE-2025-43500
- CVE-2025-43454
- CVE-2025-43418
- CVE-2025-43460
- CVE-2025-43422
- CVE-2025-43452
- CVE-2025-43480
- CVE-2025-43458
- CVE-2025-43430
- CVE-2025-43427
- CVE-2025-43443
- CVE-2025-43441
- CVE-2025-43435
- CVE-2025-43425
- CVE-2025-43440
- CVE-2025-43438
- CVE-2025-43457
- CVE-2025-43434
- CVE-2025-43495
- CVE-2025-43433
- CVE-2025-43431
- CVE-2025-43432
- CVE-2025-43429
- CVE-2025-43421
- CVE-2025-43392
Frequently Asked Questions
What is the severity of CVE-2025-43460?
CVE-2025-43460 is categorized as a logic issue that may allow an attacker with physical access to view sensitive user information.
How do I fix CVE-2025-43460?
To fix CVE-2025-43460, update your device to iOS or iPadOS version 26.1.
What devices are affected by CVE-2025-43460?
CVE-2025-43460 affects devices running iOS and iPadOS versions prior to 26.1.
What are the potential risks associated with CVE-2025-43460?
The potential risks of CVE-2025-43460 include unauthorized access to sensitive user information on a locked device.
When was CVE-2025-43460 addressed?
CVE-2025-43460 was addressed in the software updates released on iOS 26.1 and iPadOS 26.1.