CVE-2025-43230
BaseFortify
Publication date: 2025-07-30
Last updated on: 2026-04-02
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | ipados | to 17.7.9 (exc) |
| apple | ipados | From 18.0 (inc) to 18.6 (exc) |
| apple | iphone_os | to 18.6 (exc) |
| apple | macos | to 15.6 (exc) |
| apple | tvos | to 18.6 (exc) |
| apple | visionos | to 2.6 (exc) |
| apple | watchos | to 11.6 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves an issue where an app may be able to access user-sensitive data due to insufficient permissions checks. It was addressed by adding additional permissions checks in various Apple operating systems.
How can this vulnerability impact me? :
The vulnerability could allow an app to access sensitive user data without proper authorization, potentially leading to privacy breaches or unauthorized data exposure.
What immediate steps should I take to mitigate this vulnerability?
Update your devices to the fixed versions: iPadOS 17.7.9, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, or tvOS 18.6 to ensure the additional permissions checks are applied and prevent apps from accessing user-sensitive data.