CVE-2025-43537: Path Traversal
A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.
Other sources
Accessibility. An inconsistent user interface issue was addressed with improved state management.
— Apple
App Store. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. The issue was addressed with improved bounds checks.
— Apple
BiometricKit. A logic issue was addressed with improved validation.
— Apple
Books. A path handling issue was addressed with improved validation.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-20645
- CVE-2025-43537
- CVE-2026-20660
- CVE-2026-20611
- CVE-2026-20609
- CVE-2026-20634
- CVE-2026-20675
- CVE-2026-20671
- CVE-2026-20663
- CVE-2025-59375
- CVE-2026-20655
- CVE-2026-20673
- CVE-2026-20677
- CVE-2026-20616
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2026-20656
- CVE-2026-20628
- CVE-2026-20678
- CVE-2026-20682
- CVE-2026-20653
- CVE-2026-20680
- CVE-2026-20641
- CVE-2026-20606
- CVE-2026-20605
- CVE-2026-20661
- CVE-2026-20608
- CVE-2026-20652
- CVE-2026-20644
- CVE-2026-20635
- CVE-2026-20621
- CVE-2025-46288
- CVE-2025-43539
- CVE-2025-46286
- CVE-2025-46287
- CVE-2024-7264
- CVE-2025-9086
- CVE-2025-43542
- CVE-2025-43518
- CVE-2025-43532
- CVE-2025-46279
- CVE-2025-43534
- CVE-2025-46285
- CVE-2025-5918
- CVE-2025-46311
- CVE-2025-43475
- CVE-2025-46276
- CVE-2025-43428
- CVE-2025-46277
- CVE-2025-43538
- CVE-2025-46290
- CVE-2025-46292
- CVE-2025-43541
- CVE-2025-43536
- CVE-2025-43535
- CVE-2025-46298
- CVE-2025-43501
- CVE-2025-43531
- CVE-2025-14174
- CVE-2025-43529
- CVE-2025-46299
- CVE-2025-43511
Frequently Asked Questions
What is the severity of CVE-2025-43537?
CVE-2025-43537 is considered a significant vulnerability due to its potential to allow modification of protected system files.
How do I fix CVE-2025-43537?
To fix CVE-2025-43537, you should update to iOS 18.7.5 or iPadOS 18.7.5.
What type of issue is addressed by CVE-2025-43537?
CVE-2025-43537 addresses a path handling issue that involves improved validation.
Which versions of iOS are affected by CVE-2025-43537?
CVE-2025-43537 affects iOS versions up to but not including 18.7.5.
Which versions of iPadOS are impacted by CVE-2025-43537?
CVE-2025-43537 impacts iPadOS versions up to but not including 18.7.5.