CVE-2025-43309
📋 TL;DR
This CVE describes a lock screen notification vulnerability in iOS/iPadOS where an attacker with physical access can view notification contents that should be hidden. It affects iOS/iPadOS versions before 26. The vulnerability requires physical device access to exploit.
💻 Affected Systems
- iPhone
- iPad
📦 What is this software?
Ipados by Apple
⚠️ Risk & Real-World Impact
Worst Case
An attacker with brief physical access could read sensitive notifications (messages, emails, alerts) that should be protected by the lock screen, potentially exposing confidential information.
Likely Case
Someone with temporary physical access (co-worker, family member, thief) could briefly view notifications on a locked device, exposing personal or work information.
If Mitigated
With proper physical security controls and updated software, the risk is minimal as the attacker needs physical access and the vulnerability is patched.
🎯 Exploit Status
Exploitation requires physical access to the device. No authentication bypass needed as the device is locked.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: iOS 26, iPadOS 26
Vendor Advisory: https://support.apple.com/en-us/125108
Restart Required: Yes
Instructions:
1. Open Settings app. 2. Go to General > Software Update. 3. Download and install iOS/iPadOS 26 or later. 4. Device will restart automatically.
🔧 Temporary Workarounds
Disable lock screen notifications
allPrevent notifications from appearing on lock screen entirely
Enable notification privacy
allShow only sender information without message content on lock screen
🧯 If You Can't Patch
- Disable all lock screen notifications in Settings > Notifications > Show Previews
- Implement strict physical security controls for devices
- Use device passcodes with short timeout settings
🔍 How to Verify
Check if Vulnerable:
Check iOS/iPadOS version in Settings > General > About > Software Version. If version is earlier than 26, device is vulnerable.
Check Version:
Not applicable - check via device Settings UI
Verify Fix Applied:
Verify iOS/iPadOS version is 26 or later in Settings > General > About > Software Version.
📡 Detection & Monitoring
Log Indicators:
- No specific log indicators as this is a physical access vulnerability
Network Indicators:
- No network indicators
SIEM Query:
Not applicable - physical access vulnerability