CVE-2025-43449
7.5Apple · iOS and iPadOS
A cache handling vulnerability in Apple iOS and iPadOS allows a malicious application to track users across multiple installations.
Executive summary
A vulnerability in Apple iOS and iPadOS allows unauthorized user tracking, posing a significant risk to individual privacy and data anonymity.
Vulnerability
The vulnerability involves improper cache management, which permits an unauthenticated malicious application to track users across separate installations of the software.
Business impact
The ability for a malicious application to persistently track users between installs can lead to unauthorized profiling and the aggregation of sensitive user data over time. With a CVSS score of 7.5, this high-severity flaw represents a significant risk to user privacy and compliance with data protection regulations, potentially leading to reputational damage for organizations relying on these platforms for secure mobile operations.
Remediation
Immediate Action: Update all affected devices to iOS 26.1 or iPadOS 26.1 or later versions to apply the security fix.
Proactive Monitoring: Review mobile device management logs for unusual application behavior or unexpected persistence of cached data between app re-installations.
Compensating Controls: Implement robust mobile application vetting processes and restrict the installation of applications from untrusted or unverified sources.
Exploitation status
Public Exploit Available: exploit_available (false)
Analyst recommendation
Given the potential for persistent user tracking, it is imperative that administrators prioritize the deployment of the 26.1 update across their mobile fleets. Organizations should ensure that all managed devices are updated immediately to mitigate the risk of unauthorized data collection and to maintain the privacy of their user base.