Description
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.
Published: 2025-11-05
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive user information disclosure
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows an attacker who has physical access to a locked Apple device to view sensitive user information. The flaw occurs because the lock screen still presents options that expose data, representing an improper access control weakness (CWE‑284). The impact is limited to information disclosure, with no remote execution or denial‑of‑service effect described.

Affected Systems

Apple iOS and iPadOS devices are affected. The issue persists in any operating system release before iOS 18.7.2, iPadOS 18.7.2, iOS 26.1 or iPadOS 26.1. Versions released after these updates contain the fix.

Risk and Exploitability

The CVSS score of 4.6 indicates moderate severity, and the EPSS score of less than 1 % shows a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers must physically access the locked device and the affected option must be visible on the lock screen, confining the risk to environments where the device is left unattended or where an attacker can gain nearby access.

Generated by OpenCVE AI on April 27, 2026 at 22:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to iOS 18.7.2 or later, or to iPadOS 18.7.2 or later (also available in iOS 26.1 / iPadOS 26.1)
  • If an upgrade is not possible, remove physical access to the device or place it in a secure, monitored location
  • Where device‑management tools are available, disable unnecessary lock‑screen options or enforce passcode restrictions to reduce the attack surface

Generated by OpenCVE AI on April 27, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 23:15:00 +0000

Type Values Removed Values Added
Title Physical Access to Locked Device Allows Sensitive Information Disclosure

Wed, 17 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An attacker with physical access to a locked device may be able to view sensitive user information. This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.
References

Fri, 07 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 06 Nov 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Apple ipad Os
Vendors & Products Apple
Apple ios
Apple ipad Os

Wed, 05 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Nov 2025 18:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An attacker with physical access to a locked device may be able to view sensitive user information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:15:26.401Z

Reserved: 2025-04-16T15:24:37.123Z

Link: CVE-2025-43418

cve-icon Vulnrichment

Updated: 2025-11-05T18:50:39.935Z

cve-icon NVD

Status : Modified

Published: 2025-11-05T19:15:53.653

Modified: 2025-12-17T21:16:00.790

Link: CVE-2025-43418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T23:00:13Z

Weaknesses