CVE-2025-43357
published 2025-09-15CVE-2025-43357: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia…
PriorityP410low3.3CVSS 3.1
AVLACLPRNUIRSUCLINAN
EPSS
0.21%
11.9th percentile
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to fingerprint the user.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_26_and_ipados | — | — |
| apple | ios_and_ipados | < 18.7 | 18.7 |
| apple | ios_and_ipados | < 26 | 26 |
| apple | ipados | < 26.0 | 26.0 |
| apple | iphone_os | < 26.0 | 26.0 |
| apple | macos | < 14.8 | 14.8 |
| apple | macos | < 15.7 | 15.7 |
| apple | macos | < 26 | 26 |
| apple | macos | < 26.0 | 26.0 |
| apple | macos_tahoe | — | — |
| msrc | azl3_libsass_3.6.6-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2025-43357: macOS Tahoe 26
vendor_apple·2025-09-15·CVSS 3.3
CVE-2025-43357 [LOW] CVE-2025-43357: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43357
Component: Call History
Impact: An app may be able to fingerprint the user
Description: This issue was addressed with improved redaction of sensitive information.
Apple
CVE-2025-43357: iOS 26 and iPadOS 26
vendor_apple·2025-09-15·CVSS 3.3
CVE-2025-43357 [LOW] CVE-2025-43357: iOS 26 and iPadOS 26
Apple Security Update: About the security content of iOS 26 and iPadOS 26
Product: iOS 26 and iPadOS
Version: 26
CVE: CVE-2025-43357
Component: Call History
Impact: An app may be able to fingerprint the user
Description: This issue was addressed with improved redaction of sensitive information.
Microsoft
Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (D
vendor_msrc·2023-08-08·CVSS 7.5
CVE-2022-43357 [HIGH] CWE-787 Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (D
Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information.
VulDB
Apple macOS up to 18.4 App information disclosure
vuldb·2026-05-27·CVSS 3.3
CVE-2025-43357 [LOW] Apple macOS up to 18.4 App information disclosure
A vulnerability, which was classified as problematic, has been found in Apple macOS. Affected by this issue is some unknown functionality of the component App. This manipulation causes information disclosure.
This vulnerability is registered as CVE-2025-43357. The attack needs to be launched locally. No exploit is available.
It is advisable to upgrade the affected component.
VulDB
Apple iOS/iPadOS up to 18.7 App information disclosure
vuldb·2026-05-27·CVSS 3.3
CVE-2025-43357 [LOW] Apple iOS/iPadOS up to 18.7 App information disclosure
A vulnerability classified as problematic was found in Apple iOS and iPadOS. Affected by this vulnerability is an unknown functionality of the component App. The manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2025-43357. The attack must be initiated from a local position. There is no exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-jjmm-j7cw-r45w: This issue was addressed with improved redaction of sensitive information
ghsa_unreviewed·2025-09-16
CVE-2025-43357 [LOW] CWE-359 GHSA-jjmm-j7cw-r45w: This issue was addressed with improved redaction of sensitive information
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Tahoe 26, iOS 26 and iPadOS 26. An app may be able to fingerprint the user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-15
Published