CVE-2025-43350

7.5

Apple · iOS and iPadOS

A permissions vulnerability in Apple iOS and iPadOS allows unauthenticated attackers with physical access to view restricted content directly from the lock screen.

Executive summary

A physical access permission vulnerability in Apple iOS and iPadOS allows unauthorized viewing of restricted content from the lock screen, posing a risk to user privacy.

Vulnerability

This is a permissions issue where the device fails to properly restrict access to sensitive data on the lock screen. An unauthenticated attacker with physical proximity to the device can bypass standard access controls to view restricted content.

Business impact

The exploitation of this vulnerability results in unauthorized access to sensitive information stored on mobile devices. While the CVSS score of 7.5 indicates a high severity, the requirement for physical access necessitates a localized threat model. However, for organizations managing sensitive data on mobile hardware, this flaw represents a significant risk to data confidentiality and compliance.

Remediation

Immediate Action: Update all affected devices to iOS 26.1 or iPadOS 26.1 or later versions immediately.

Proactive Monitoring: Monitor device management consoles for any anomalous physical access reports or unauthorized login attempts on managed hardware.

Compensating Controls: Enforce strict device locking policies and utilize mobile device management (MDM) solutions to remotely wipe or lock devices if physical security is compromised.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for unauthorized information disclosure, organizations should prioritize the deployment of the 26.1 update across all corporate-managed mobile assets. Ensuring devices are running the latest firmware is the only effective way to remediate this permission-based access flaw.

More Apple CVEs

Sources