CVE-2025-43452

7.5

Apple · iOS and iPadOS

A vulnerability in Apple iOS and iPadOS allows keyboard suggestions to display sensitive information while a device is locked.

Executive summary

Apple iOS and iPadOS are affected by a lock screen information disclosure vulnerability that could expose sensitive data to unauthorized individuals with physical access.

Vulnerability

This is an information disclosure vulnerability where the keyboard suggestion feature inadvertently reveals sensitive information on the device lock screen. The vulnerability requires physical access to the device (AV:P) and does not require user interaction or authentication to trigger.

Business impact

The ability for an unauthorized party to view sensitive information on a locked device poses a significant risk to data confidentiality. With a CVSS score of 7.5, this high-severity flaw could lead to the exposure of private communications, credentials, or personal data, resulting in potential privacy violations and compliance failures for users handling corporate data.

Remediation

Immediate Action: Update all affected Apple devices to iOS 26.1 or iPadOS 26.1 or later versions.

Proactive Monitoring: Review device access logs and monitor for unusual physical access attempts or unauthorized device usage patterns.

Compensating Controls: If immediate updates are not feasible, consider disabling predictive keyboard suggestions in device settings as a temporary measure to minimize exposure.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high impact on data privacy, administrators and users should prioritize the deployment of the provided security updates. Ensuring that all mobile endpoints are running the latest software version is essential to remediate this information disclosure risk and protect sensitive data from physical access threats.

More Apple CVEs

Sources