Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker may be able to view restricted content from the lock screen.
Published: 2025-11-04
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Disclosure
Action: Apply Patch
AI Analysis

Impact

A permissions misconfiguration allows a user to view content that is meant to remain hidden when the device is locked. The flaw is a classic privilege management issue, identified as CWE‑276, where software permits access to restricted resources without verifying the lock‑screen state. The consequence is that an attacker who has physical access to the device can see otherwise protected data such as sensitive notifications or preview content, compromising user privacy.

Affected Systems

Apple iOS and iPadOS devices affected by this issue are older releases that have not yet been updated to version 26.1. The vulnerability applies broadly to both iPhone and iPad operating systems, as both share the same lock‑screen code path for displaying restricted content.

Risk and Exploitability

The CVSS score of 2.4 classifies this flaw as low severity, and the EPSS score of less than 1 % indicates that real‑world exploitation is very unlikely. It is not listed in the CISA KEV catalog. The attack vector is inferred to be local: an attacker must have physical access to the device while it is locked and then view content presented on the lock screen. No remote code execution or denial of service capability is described. Given the low score and minimal exploitation probability, the overall risk to users is modest, but the privacy breach remains significant.

Generated by OpenCVE AI on April 28, 2026 at 10:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to iOS 26.1 or iPadOS 26.1 to apply the vendor‑provided permission fix.
  • Disable lock‑screen previews for sensitive applications in Settings > Notifications or using Screen Time restrictions.
  • Enable a strong lock‑screen authentication (passcode or biometric) to protect the device.

Generated by OpenCVE AI on April 28, 2026 at 10:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 28 Apr 2026 11:00:00 +0000

Type Values Removed Values Added
Title View Restricted Content from Lock Screen

Wed, 05 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 04 Nov 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple iphone Os

Tue, 04 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Apple ipados
Vendors & Products Apple
Apple ios
Apple ipados

Tue, 04 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker may be able to view restricted content from the lock screen.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:08:26.948Z

Reserved: 2025-04-16T15:24:37.111Z

Link: CVE-2025-43350

cve-icon Vulnrichment

Updated: 2025-11-04T16:03:10.946Z

cve-icon NVD

Status : Modified

Published: 2025-11-04T02:15:42.240

Modified: 2025-11-05T15:15:34.497

Link: CVE-2025-43350

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T10:45:29Z

Weaknesses