CVE-2025-43450
7.5Apple · iOS and iPadOS
A logic flaw in Apple iOS and iPadOS allows an application to access information about the current camera view prior to receiving formal user permission.
Executive summary
An unauthenticated logic vulnerability in Apple iOS and iPadOS allows applications to bypass privacy controls and access camera preview data without user authorization.
Vulnerability
This vulnerability is a logic flaw where an application can gain unauthorized visibility into the camera feed before the system grants explicit camera access permissions to the app. The vulnerability is unauthenticated, as it involves a systemic failure in the operating system access control mechanism.
Business impact
This vulnerability poses a significant privacy risk by allowing potentially malicious applications to capture sensitive visual information without the user's consent. With a CVSS score of 7.5, the issue is considered high severity because it enables unauthorized surveillance and data exfiltration. Organizations relying on mobile devices for sensitive operations face potential reputational and compliance risks if employees use devices that allow unauthorized camera access.
Remediation
Immediate Action: Update all affected devices to iOS 18.7.2 or iOS 26.1 immediately to resolve the logic error.
Proactive Monitoring: Review application permissions and audit installed apps for suspicious behavior or requests for unnecessary hardware access.
Compensating Controls: Until devices are updated, users should exercise caution when granting permissions to untrusted or third party applications.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high severity of this privacy-related vulnerability, administrators must prioritize the deployment of the provided security updates. Ensuring all devices are running the patched versions of iOS and iPadOS is the only definitive way to prevent unauthorized applications from accessing the camera feed. Verify that all corporate-managed devices have successfully received the update to maintain compliance and security.