CVE-2025-43444
BaseFortify
Publication date: 2025-11-04
Last updated on: 2026-04-02
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | ipados | to 26.1 (exc) |
| apple | iphone_os | to 26.1 (exc) |
| apple | tvos | to 26.1 (exc) |
| apple | visionos | to 26.1 (exc) |
| apple | watchos | to 26.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a permissions issue that was addressed by adding additional restrictions. It could allow an app to fingerprint the user, meaning the app might be able to uniquely identify or track the user based on device or usage characteristics.
How can this vulnerability impact me? :
The vulnerability could impact you by allowing an app to fingerprint you, potentially compromising your privacy by tracking or identifying you without your consent.
What immediate steps should I take to mitigate this vulnerability?
Update your devices to watchOS 26.1, iOS 26.1, iPadOS 26.1, tvOS 26.1, or visionOS 26.1 as these versions contain the fix for this vulnerability.