CVE-2025-43459: Apple watchOS

Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.

An authentication issue was addressed with improved state management. This issue is fixed in watchOS 26.1. An attacker with physical access to a locked Apple Watch may be able to view Live Voicemail.

Affected products

  • Apple watchOS: before 26.1 (fixed in 26.1)

Published 2025-11-04. Last modified 2026-06-17.