CVE-2025-43203
Apple Ipados ≤ 18.7
Raw vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NSummary
CVE-2025-43203 is a medium-severity Insecure Storage of Sensitive Information (CWE-922) vulnerability in Apple Ipados. Its CVSS base score is 4.0 (Medium).
Operationally, ranked at the 12th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and SC-28 (Protection of Information at Rest) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-29344
Vulnerability Data
The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An attacker with physical access to an unlocked device may be able to view an image…
more
in the most recently viewed locked note.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly requires protection of sensitive information (note images) at rest so that cache remnants cannot be read after the note is locked.
Enforces access-control decisions on locked notes, ensuring their cached content remains inaccessible even on an unlocked device.
Strengthens device- and application-level locking behavior that should clear or isolate note caches when a note transitions to the locked state.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Secure reuse and disposal procedures, including cryptographic wiping and physical destruction, stop the insecure storage of sensitive data on media that may later be accessed by unauthorized actors.
Mandating secure disposal techniques stops the insecure retention of sensitive information on storage media that leaves organizational control.