---
id: CVE-2025-43418
title: This issue was addressed by restricting options offered on a locked device
summary: >-
  This issue was addressed by restricting options offered on a locked device.
  This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1.
  An attacker with physical access to a locked device may be able to view
  sensitive …
severity: medium
cvss: 4.6
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-284
vendor: apple
product: ipados
affected:
  - ipados < 18.7.2
  - iphone_os < 18.7.2
patched:
  - ipados 18.7.2
  - iphone_os 18.7.2
published: '2025-11-05'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-43418'
references:
  - url: 'https://support.apple.com/en-us/125632'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/125633'
    label: product-security@apple.com
tags:
  - nvd
epss: 0.0018
epssPercentile: 0.06794
ingestedAt: '2026-09-26T00:22:39.975Z'
---

## Overview

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.

## Affected

- `ipados < 18.7.2`
- `iphone_os < 18.7.2`

## Remediation

Upgrade past the affected range:

- `ipados 18.7.2`
- `iphone_os 18.7.2`
