CVE-2025-43408
BaseFortify
Publication date: 2025-11-04
Last updated on: 2026-04-02
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | macos | to 14.8.2 (exc) |
| apple | macos | From 15.0 (inc) to 15.7.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability allows an attacker with physical access to a locked Apple device to potentially access contacts from the lock screen. The issue was addressed by restricting the options available on a locked device to prevent such unauthorized access.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow someone with physical access to your locked device to view your contacts without unlocking the device, potentially exposing personal or sensitive contact information.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update your macOS to version Sonoma 14.8.2 or Sequoia 15.7.2, which include the fix that restricts options on a locked device to prevent unauthorized access to contacts from the lock screen.