CVE-2026-43657: Apple iPhone OS
Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malicious app may be able to enumerate installed apps.
Affected products
- Apple iPhone OS: before 26.5 (fixed in 26.5)
Published 2026-08-25. Last modified 2026-08-31.