CVE-2025-43436
BaseFortify
Publication date: 2025-11-04
Last updated on: 2026-04-02
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | ipados | to 26.1 (exc) |
| apple | iphone_os | to 26.1 (exc) |
| apple | tvos | to 26.1 (exc) |
| apple | visionos | to 26.1 (exc) |
| apple | watchos | to 26.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-288 | The product requires authentication, but the product has an alternate path or channel that does not require authentication. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a permissions issue that allowed an app to enumerate a user's installed apps. It was addressed by adding additional restrictions in watchOS 26.1, iOS 26.1, iPadOS 26.1, tvOS 26.1, and visionOS 26.1.
How can this vulnerability impact me? :
An app exploiting this vulnerability could potentially gather information about what other apps are installed on your device, which may lead to privacy concerns or targeted attacks based on the apps you use.
What immediate steps should I take to mitigate this vulnerability?
Update your device to watchOS 26.1, iOS 26.1, iPadOS 26.1, tvOS 26.1, or visionOS 26.1 as these versions contain the fix for this permissions issue.