ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Apple issues fixes for vulnerabilities in both old and new OS versions

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-24200
Incorrect Authorization in Apple iOS/iPadOS Lets Attackers Disable USB Restricted Mode

CVE-2025-24200 is an incorrect authorization flaw (CWE-863) in Apple iOS and iPadOS, caused by an authorization issue in state management that Apple resolved with improved state handling. An attacker with brief physical access to a locked device can exploit the flaw to disable USB Restricted Mode, the feature that locks down a locked iPhone or iPad's USB data port against accessories after a set period. This allows USB accessories, including data-extraction and attack peripherals, to communicate with the device while it remains locked, with a high confidentiality and integrity impact (CVSS 6.1, physical attack vector). Any iPhone or iPad user running a version prior to the applicable fixed release is affected, with fixes shipped in iOS 15.8.4, iOS 16.7.11, iOS 18.3.1, iPadOS 15.8.4, iPadOS 16.7.11, iPadOS 17.7.5, and iPadOS 18.3.1. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-12.

Do: Update iPhones to iOS 15.8.4, iOS 16.7.11, or iOS 18.3.1 and iPads to iPadOS 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable to each device's branch, checking Settings > General > Software Update for unmanaged devices. Because exploitation requires physical access, prioritize high-risk users (executives, journalists, government personnel), confirm no fleet devices remain on unpatched builds, and avoid untrusted USB accessories and charging ports until updated. CISA's KEV listing requires federal agencies to apply the vendor patch per the required action or discontinue use of the product.

6.14% KEV
  • Apple iOS (iPhone) Versions prior to the fixed releases in each branch: iOS < 15.8.4, iOS < 16.7.11, and iOS < 18.3.1
  • Apple iPadOS (iPad) Versions prior to the fixed releases in each branch: iPadOS < 15.8.4, iPadOS < 16.7.11, iPadOS < 17.7.5, and iPadOS < 18.3.1
mass≈1 billion+ devices (Apple's active installed base; every iPhone/iPad running a pre-patch iOS/iPadOS release at the time of disclosure)
CVE-2025-24201
WebKit Out-of-Bounds Write Sandbox Escape in Apple iOS, Safari, and macOS

CVE-2025-24201 is an out-of-bounds write (CWE-787) in WebKit, the web rendering engine used across Apple's platforms, which Apple addressed with improved bounds checks. It is triggered by processing maliciously crafted web content, meaning a victim only has to load attacker-controlled web content in Safari or in any app that renders web content. A successful attacker can break out of the Web Content sandbox and perform unauthorized actions, an impact CISA scores at CVSS 10.0 (critical, scope-changing). Affected users include anyone running vulnerable versions of iOS, iPadOS, macOS Sequoia, Safari, visionOS, or watchOS; Debian Linux is also listed in the CPE data because Debian ships WebKit in its webkit packages. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2 (this patch is a supplementary fix for that previously blocked attack, extended to older branches), and the CVE was added to CISA's KEV catalog on 2025-03-13.

Do: Apply the vendor fixes immediately: Safari 18.3.1; iOS/iPadOS 18.3.2 (or 17.7.6, 16.7.11, or 15.8.4 on devices that cannot run the newest release); macOS Sequoia 15.3.2; visionOS 2.3.2; watchOS 11.4; and updated Debian webkit packages per Debian advisories. Because the CVE is in CISA's KEV catalog (added 2025-03-13), US federal agencies must patch per BOD 22-01, and all defenders should prioritize fleets with high-risk or frequently targeted users. Given the 'extremely sophisticated' targeted exploitation against individuals on iOS before 17.2, check whether targeted or high-value users' devices show indicators of compromise and ensure they are not left on older branches.

10.04% KEV
  • Apple Safari Versions prior to 18.3.1; fixed in Safari 18.3.1
  • Apple iPhone OS (iOS) iOS 15.x, 16.x and 18.x prior to the fixes; fixed in iOS 15.8.4, iOS 16.7.11, and iOS 18.3.2 (the referenced in-the-wild attacks targeted iOS versions before 17
  • Apple iPadOS iPadOS 15.x, 16.x, 17.x and 18.x prior to the fixes; fixed in iPadOS 15.8.4, 16.7.11, 17.7.6, and 18.3.2
  • +4 more
mass≈2 billion+ active Apple devices (iPhone, iPad, Mac, Apple Watch and Vision Pro all ship the affected WebKit; Apple publicly reports an active installed base…
CVE-2025-24221
This issue was addressed with improved data access restriction.

This issue was addressed with improved data access restriction. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, visionOS 2.4. Sensitive keychain data may be accessible from an iOS backup.

NVD description · AI analysis pending
7.5<1%
  • apple ipados
  • apple iphone os
  • apple visionos
CVE-2025-24245
This issue was addressed by adding a delay between verification code attempts.

This issue was addressed by adding a delay between verification code attempts. This issue is fixed in macOS Sequoia 15.4. A malicious app may be able to access a user's saved passwords.

NVD description · AI analysis pending
9.8<1%
  • apple macos
Full article507 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The company released a host of security patches Monday, including ones that address two zero-day vulnerabilities.

Listen to this article

0:00

Learn more.

The Apple Inc logo is displayed outside a retail store at the Third Street Promenade in Santa Monica, California on March 20, 2023. (Photo by PATRICK T. FALLON/AFP via Getty Images)

Apple released security updates Monday to address software defects in the latest version of the company’s Safari browser and other applications across iOS, iPadOS and macOS. 

The security issues addressed across the latest versions of Apple’s most popular platforms include 62 vulnerabilities affecting iOS 18.4 and iPadOS 18.4, 131 vulnerabilities affecting macOS Sequoia 15.4 and 14 vulnerabilities affecting Safari 18.4.

The batch of software defects addressed by Apple includes CVE-2025-24221, which could make sensitive keychain data accessible from an iOS backup, and CVE-2025-24245, which could allow an attacker to use a malicious application to access a user’s saved passwords in macOS.

Apple also released security updates in older versions of its operating systems to address two actively exploited zero-day vulnerabilities it identified and released emergency software patches for March 11. 

A zero-day vulnerability in the company’s WebKit web browser engine, tracked as CVE-2025-24201, can allow an attacker to break out of WebKit’s Web Content sandbox and potentially conduct unauthorized actions. The second zero-day, CVE-2025-24200, can allow an attacker with physical access to disable USB Restricted Mode on a locked device.

Apple said both zero-days were actively exploited in an “extremely sophisticated attack against specific target individuals.” Apple released security updates Monday to address the zero-days in iOS 15.8.4 and 16.7.11, and iPadOS 15.8.4 and 16.7.11, versions of the company’s operating systems that power previous generation iPhones and iPads.

More information about Apple’s latest security updates are available on its website.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/apple-security-update-march-2025/