A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.
References
| Link | Resource |
|---|---|
| https://support.apple.com/en-us/125884 | |
| https://support.apple.com/en-us/126347 | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-02-11 23:16
Updated : 2026-06-17 09:24
NVD link : CVE-2025-43537
Mitre link : CVE-2025-43537
CVE.ORG link : CVE-2025-43537
JSON object : View
Products Affected
apple
- iphone_os
- ipados
CWE
NVD-CWE-noinfo
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
