CVE-2025-43534: Use After Free
802.1X. An authentication issue was addressed with improved state management.
Other sources
A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.2 and iPadOS 26.2. A user with physical access to an iOS device may be able to bypass Activation Lock.
— MITRE
App Store. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. The issue was addressed with improved bounds checks.
— Apple
AppleKeyStore. A use after free issue was addressed with improved memory management.
— Apple
Audio. A use-after-free issue was addressed with improved memory management.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-46288
- CVE-2025-43539
- CVE-2025-46286
- CVE-2025-43537
- CVE-2025-46287
- CVE-2024-7264
- CVE-2025-9086
- CVE-2025-43542
- CVE-2025-43518
- CVE-2025-43532
- CVE-2025-46279
- CVE-2025-43534
- CVE-2025-46285
- CVE-2025-5918
- CVE-2025-46311
- CVE-2025-43475
- CVE-2025-46276
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2025-43428
- CVE-2025-46277
- CVE-2025-43538
- CVE-2025-46290
- CVE-2025-46292
- CVE-2025-43541
- CVE-2025-43536
- CVE-2025-43535
- CVE-2025-46298
- CVE-2025-43501
- CVE-2025-43531
- CVE-2025-14174
- CVE-2025-43529
- CVE-2025-46299
- CVE-2025-43511
- CVE-2026-28865
- CVE-2026-20637
- CVE-2026-28879
- CVE-2026-28866
- CVE-2026-20690
- CVE-2026-28886
- CVE-2026-28878
- CVE-2025-14524
- CVE-2026-28876
- CVE-2026-20668
- CVE-2026-28880
- CVE-2025-64505
- CVE-2026-28868
- CVE-2026-28867
- CVE-2026-20687
- CVE-2026-28864
- CVE-2026-28860
- CVE-2026-28967
- CVE-2026-28852
- CVE-2026-20657
- CVE-2026-20665
- CVE-2026-20643
- CVE-2025-43376
- CVE-2026-28861
- CVE-2026-28871
Frequently Asked Questions
What is the severity of CVE-2025-43534?
The severity of CVE-2025-43534 is medium with a CVSS score of 6.8.
What types of issues does CVE-2025-43534 address?
CVE-2025-43534 addresses authentication issues and path handling vulnerabilities related to state management and input validation.
How do I fix CVE-2025-43534?
CVE-2025-43534 can be fixed by updating to iOS 18.7.7, iPadOS 18.7.7, or iOS 26.2 and iPadOS 26.2.
What devices are affected by CVE-2025-43534?
CVE-2025-43534 affects Apple iPadOS, Apple iOS, and Apple iPhone OS devices.
What could happen if CVE-2025-43534 is exploited?
If exploited, CVE-2025-43534 may allow a user with physical access to an iOS device to bypass Activation Lock.