CVE-2025-43426

MEDIUM

macOS Tahoe <26.1 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-43426. PoCs published by csrXamfi.

AI-analyzed exploit summary The repository contains only a README.md file with minimal information about CVE-2025-43426, lacking any exploit code or technical details.

Description

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to access sensitive user data.

Exploits (1)

nomisec STUB 5 stars
by csrXamfi · poc
https://github.com/csrXamfi/CVE-2025-43426

The repository contains only a README.md file with minimal information about CVE-2025-43426, lacking any exploit code or technical details.

Classification
Stub 10%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/125632

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 14.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (4)
Apple/iOS and iPadOS < 26.1
apple/ipados < 26.1
apple/iphone_os < 26.1
Apple/macOS < 26.1
Published Nov 04, 2025
Tracked Since Feb 18, 2026