CVE-2025-43422

The issue was addressed by adding additional logic. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a device may be able to disable Stolen Device Protection.
References
Link Resource
https://support.apple.com/en-us/125632 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:23

Type Values Removed Values Added
Summary
  • (es) El problema se abordó añadiendo lógica adicional. Este problema está corregido en iOS 26.1 y iPadOS 26.1. Un atacante con acceso físico a un dispositivo podría deshabilitar la Protección de Dispositivos Robados.

01 Dec 2025, 20:15

Type Values Removed Values Added
CWE CWE-288

05 Nov 2025, 15:00

Type Values Removed Values Added
First Time Apple ipados
Apple
Apple iphone Os
CWE NVD-CWE-noinfo
References () https://support.apple.com/en-us/125632 - () https://support.apple.com/en-us/125632 - Release Notes, Vendor Advisory
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

04 Nov 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6

04 Nov 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-04 02:15

Updated : 2026-06-17 09:23


NVD link : CVE-2025-43422

Mitre link : CVE-2025-43422

CVE.ORG link : CVE-2025-43422


JSON object : View

Products Affected

apple

  • ipados
  • iphone_os
CWE
NVD-CWE-noinfo CWE-288

Authentication Bypass Using an Alternate Path or Channel