CVE-2025-43190
Description
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, visionOS 26, watchOS 26. An app may be able to access sensitive user data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A path parsing vulnerability in Apple operating systems could allow an app to access sensitive user data, patched in multiple updates.
Analysis
CVE-2025-43190 is a parsing issue in the handling of directory paths in Apple operating systems. The vulnerability stems from insufficient path validation, which could allow an app to access files or directories outside its intended sandbox. Apple addressed this by improving path validation in the affected versions.
The vulnerability can be exploited by any app running on the device, with no additional user interaction required beyond installation. An attacker could craft a malicious app that uses specially crafted directory paths to bypass security restrictions. The exact attack vector is not detailed, but the parsing issue suggests possible directory traversal or symlink following.
Successful exploitation could allow the app to access sensitive user data, such as documents, photos, or other private information. The CVSS v3 base score of 5.5 (Medium) indicates moderate risk.
Apple fixed the issue in iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, visionOS 26, and watchOS 26, all released on September 15, 2025 [1][2][4]. Users should update their devices to the latest software versions to mitigate the risk.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
8cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <26.0
- (no CPE)range: <26
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*range: >=14.0,<14.8
- (no CPE)range: <15.7
- Range: <26
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- support.apple.com/en-us/125108nvdRelease NotesVendor Advisory
- support.apple.com/en-us/125111nvdRelease NotesVendor Advisory
- support.apple.com/en-us/125112nvdRelease NotesVendor Advisory
- support.apple.com/en-us/125115nvdRelease NotesVendor Advisory
- support.apple.com/en-us/125116nvdRelease NotesVendor Advisory
- seclists.org/fulldisclosure/2025/Sep/53nvd
- seclists.org/fulldisclosure/2025/Sep/54nvd
- seclists.org/fulldisclosure/2025/Sep/55nvd
- seclists.org/fulldisclosure/2025/Sep/57nvd
- seclists.org/fulldisclosure/2025/Sep/58nvd
- support.apple.com/en-us/125110nvd
News mentions
0No linked articles in our index yet.