CVE Vulnerabilities

CVE-2025-43436

Authentication Bypass Using an Alternate Path or Channel

Published: Nov 04, 2025 | Modified: Dec 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A permissions issue was addressed with additional restrictions. This issue is fixed in tvOS 26.1, watchOS 26.1, macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1, visionOS 26.1. An app may be able to enumerate a users installed apps.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
IpadosApple*26.1 (excluding)
Iphone_osApple*26.1 (excluding)
TvosApple*26.1 (excluding)
VisionosApple*26.1 (excluding)
WatchosApple*26.1 (excluding)

Potential Mitigations

References