CVE-2026-43657: Apple iPhone OS

Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malicious app may be able to enumerate installed apps.

Affected products

  • Apple iPhone OS: before 26.5 (fixed in 26.5)

Published 2026-08-25. Last modified 2026-08-31.