CVE-2025-43452
7.5Apple · iOS and iPadOS
A vulnerability in Apple iOS and iPadOS allows keyboard suggestions to display sensitive information while a device is locked.
Executive summary
Apple iOS and iPadOS are affected by a lock screen information disclosure vulnerability that could expose sensitive data to unauthorized individuals with physical access.
Vulnerability
This is an information disclosure vulnerability where the keyboard suggestion feature inadvertently reveals sensitive information on the device lock screen. The vulnerability requires physical access to the device (AV:P) and does not require user interaction or authentication to trigger.
Business impact
The ability for an unauthorized party to view sensitive information on a locked device poses a significant risk to data confidentiality. With a CVSS score of 7.5, this high-severity flaw could lead to the exposure of private communications, credentials, or personal data, resulting in potential privacy violations and compliance failures for users handling corporate data.
Remediation
Immediate Action: Update all affected Apple devices to iOS 26.1 or iPadOS 26.1 or later versions.
Proactive Monitoring: Review device access logs and monitor for unusual physical access attempts or unauthorized device usage patterns.
Compensating Controls: If immediate updates are not feasible, consider disabling predictive keyboard suggestions in device settings as a temporary measure to minimize exposure.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high impact on data privacy, administrators and users should prioritize the deployment of the provided security updates. Ensuring that all mobile endpoints are running the latest software version is essential to remediate this information disclosure risk and protect sensitive data from physical access threats.