Apple fixes zero-day flaw exploited in "extremely sophisticated" attack (CVE-2025-24200)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-24200 | Incorrect Authorization in Apple iOS/iPadOS Lets Attackers Disable USB Restricted Mode CVE-2025-24200 is an incorrect authorization flaw (CWE-863) in Apple iOS and iPadOS, caused by an authorization issue in state management that Apple resolved with improved state handling. An attacker with brief physical access to a locked device can exploit the flaw to disable USB Restricted Mode, the feature that locks down a locked iPhone or iPad's USB data port against accessories after a set period. This allows USB accessories, including data-extraction and attack peripherals, to communicate with the device while it remains locked, with a high confidentiality and integrity impact (CVSS 6.1, physical attack vector). Any iPhone or iPad user running a version prior to the applicable fixed release is affected, with fixes shipped in iOS 15.8.4, iOS 16.7.11, iOS 18.3.1, iPadOS 15.8.4, iPadOS 16.7.11, iPadOS 17.7.5, and iPadOS 18.3.1. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-12. Do: Update iPhones to iOS 15.8.4, iOS 16.7.11, or iOS 18.3.1 and iPads to iPadOS 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable to each device's branch, checking Settings > General > Software Update for unmanaged devices. Because exploitation requires physical access, prioritize high-risk users (executives, journalists, government personnel), confirm no fleet devices remain on unpatched builds, and avoid untrusted USB accessories and charging ports until updated. CISA's KEV listing requires federal agencies to apply the vendor patch per the required action or discontinue use of the product. | 6.1 | 4% | KEV |
| mass≈1 billion+ devices (Apple's active installed base; every iPhone/iPad running a pre-patch iOS/iPadOS release at the time of disclosure) |
Full article367 words · extracted from helpnetsecurity.com · click to collapse
Users of iPhones and iPads that run iOS/iPadOS 18 and iPadOS 17 are urged to implement the latest updates to plug a security feature bypass vulnerability (CVE-2025-24200) exploited in the wild in “an extremely sophisticated” attack.

The vulnerability (CVE-2025-24200)
“A physical attack may disable USB Restricted Mode on a locked device,” Apple explained.
USB Restricted Mode is a feature Apple introduced in 2018 to protect users against device unlocking (“cracking”) tools such as Graykey, usually at the hands of law enforcement.
These tools get connected to target devices via USB and can bypass passcode-based protection/encryption to extract data. USB Restricted Mode prevents them from accessing the data through this connection if iPhones and iPads haven’t been unlocked for over an hour.
CVE-2025-24200 stems from an authorization issue that has been solved with improved state management.
The security updates are available for:
- iPhone XS and later
- iPad Pro 13-inch
- iPad Pro 12.9-inch 3rd generation and later
- iPad Pro 11-inch 1st generation and later
- iPad Air 3rd generation and later
- iPad 7th generation and later
- iPad mini 5th generation and later
- iPad Pro 12.9-inch 2nd generation
- iPad Pro 10.5-inch, and
- iPad 6th generation.
The attack
“Apple is aware of a report that [CVE-2025-24200] may have been exploited in an extremely sophisticated attack against specific targeted individuals,” the company said.
The wording is pretty unusual for Apple but, unfortunately, no other details about the attack have been made available. There has also been no mention of whether the attack can be thwarted by Apple’s Lockdown Mode.
CVE-2025-24200 was flagged by Bill Marczak, a senior researcher with The Citizen Lab at The University of Toronto’s Munk School.
The Citizen Lab is known for aiding political dissidents, civil society activists and journalists who suspect that their devices have been compromised with commercial spyware such as NSO Group’s Pegasus and Intellexa’s Predator.
Their activities often lead them to discover and report zero-day vulnerabilities exploited by this malicious software.
Read more:
- The fight against commercial spyware misuse is heating up
- How widespread is mercenary spyware? More than you think

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/02/11/apple-fixes-zero-day-flaw-exploited-in-extremely-sophisticated-attack-cve-2025-24200/