CVE Vulnerabilities

CVE-2025-43436

Authentication Bypass Using an Alternate Path or Channel

Published: Nov 04, 2025 | Modified: Nov 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A permissions issue was addressed with additional restrictions. This issue is fixed in watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1, visionOS 26.1. An app may be able to enumerate a users installed apps.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Ipados Apple * 26.1 (excluding)
Iphone_os Apple * 26.1 (excluding)
Tvos Apple * 26.1 (excluding)
Visionos Apple * 26.1 (excluding)
Watchos Apple * 26.1 (excluding)

Potential Mitigations

References