CVE-2025-43203
MEDIUMiOS <26 - Info Disclosure
Title source: llmDescription
The issue was addressed with improved handling of caches. This issue is fixed in iOS 26 and iPadOS 26, iOS 18.7 and iPadOS 18.7. An attacker with physical access to an unlocked device may be able to view an image in the most recently viewed locked note.
Scores
CVSS v3
4.0
EPSS
0.0001
EPSS Percentile
2.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-922
Status
published
Affected Products (2)
apple/ipados
< 18.7
apple/iphone_os
< 18.7
Timeline
Published
Sep 15, 2025
Tracked Since
Feb 18, 2026