CVE-2025-43426Medium· 5.5▾ TwilightPoC availableA logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to access sensitive user data.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 30.3 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
1 GitHub repo (last check)
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to access sensitive user data.
ipados < 26.1iphone_os < 26.1Upgrade past the affected range:
ipados 26.1iphone_os 26.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-43423Low· 2.0A logging issue was addressed with improved data redaction
CVE-2025-43507Medium· 6.5A privacy issue was addressed by moving sensitive data
CVE-2025-43445Medium· 4.3An out-of-bounds read was addressed with improved input validation
CVE-2025-43448Medium· 6.3This issue was addressed with improved validation of symlinks
CVE-2025-43444Medium· 5.3A permissions issue was addressed with additional restrictions
CVE-2025-43384Medium· 4.3An out-of-bounds access issue was addressed with improved bounds checking