Description
A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.
Published: 2026-02-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Modification of protected system files
Action: Patch
AI Analysis

Impact

A path handling flaw in iOS and iPadOS devices permits an attacker to craft a malicious backup file that, when restored, can modify protected system files. This flaw is a path traversal weakness (CWE‑22) that directly compromises system integrity. The vulnerability does not affect confidentiality or availability but allows an attacker to alter critical OS files, potentially undermining device stability and security.

Affected Systems

Apple iOS and iPadOS devices running any version older than iOS 18.7.5 or iPadOS 18.7.5 (and older than iOS 26.2 or iPadOS 26.2) are susceptible. Devices with those older releases must be considered vulnerable until an update is applied.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate risk level. The EPSS score below 1 % suggests that exploitation is unlikely but possible. The catalog entry is not currently listed in CISA’s KEV. The flaw is exploitable locally by restoring a crafted backup file; an attacker needs access to the device’s backup restoration process or a compromised backup file. Once the backup is restored, the attacker can modify protected system files, compromising integrity.

Generated by OpenCVE AI on April 22, 2026 at 20:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to iOS 18.7.5, iOS 26.2, iPadOS 18.7.5, or iPadOS 26.2 to apply the fix.
  • Avoid restoring backups from untrusted or unknown sources until after updating the OS.
  • Verify that backup files are encrypted and sourced from legitimate backups before restoration.

Generated by OpenCVE AI on April 22, 2026 at 20:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Title Backup Restoration Path Handling Issue Allows Modification of Protected System Files

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5. Restoring a maliciously crafted backup file may lead to modification of protected system files. A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.
References

Thu, 26 Feb 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Fri, 13 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Thu, 12 Feb 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Vendors & Products Apple
Apple ios And Ipados

Wed, 11 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5. Restoring a maliciously crafted backup file may lead to modification of protected system files.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:07:09.734Z

Reserved: 2025-04-16T15:27:21.198Z

Link: CVE-2025-43537

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2026-02-11T23:16:02.300

Modified: 2026-04-02T19:21:01.487

Link: CVE-2025-43537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T20:15:20Z

Weaknesses