Apple fixes security flaw allowing third
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-24200 | Incorrect Authorization in Apple iOS/iPadOS Lets Attackers Disable USB Restricted Mode CVE-2025-24200 is an incorrect authorization flaw (CWE-863) in Apple iOS and iPadOS, caused by an authorization issue in state management that Apple resolved with improved state handling. An attacker with brief physical access to a locked device can exploit the flaw to disable USB Restricted Mode, the feature that locks down a locked iPhone or iPad's USB data port against accessories after a set period. This allows USB accessories, including data-extraction and attack peripherals, to communicate with the device while it remains locked, with a high confidentiality and integrity impact (CVSS 6.1, physical attack vector). Any iPhone or iPad user running a version prior to the applicable fixed release is affected, with fixes shipped in iOS 15.8.4, iOS 16.7.11, iOS 18.3.1, iPadOS 15.8.4, iPadOS 16.7.11, iPadOS 17.7.5, and iPadOS 18.3.1. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-12. Do: Update iPhones to iOS 15.8.4, iOS 16.7.11, or iOS 18.3.1 and iPads to iPadOS 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable to each device's branch, checking Settings > General > Software Update for unmanaged devices. Because exploitation requires physical access, prioritize high-risk users (executives, journalists, government personnel), confirm no fleet devices remain on unpatched builds, and avoid untrusted USB accessories and charging ports until updated. CISA's KEV listing requires federal agencies to apply the vendor patch per the required action or discontinue use of the product. | 6.1 | 4% | KEV |
| mass≈1 billion+ devices (Apple's active installed base; every iPhone/iPad running a pre-patch iOS/iPadOS release at the time of disclosure) |
Full article270 words · extracted from therecord.media · click to collapse
Apple on Monday announced it has fixed its mobile operating systems in response to a newly uncovered vulnerability that the company said may have been used in an “extremely sophisticated attack against specific targeted individuals.” The flaw allowed third parties to “disable” restricted mode “on a locked device,” according to information the company posted on its website. No details were available about where or when the incident occurred. The vulnerability, as described, could have been used to enable unlocking technology similar to Cellebrite products, which allow snoopers to break into devices when they have physical access to them. Cellebrite is widely used by law enforcement and was reportedly deployed to access data stored in the phone of a man who tried to assassinate President Donald Trump in July. Apple’s restricted mode blocks data access to iPhones and iPads when they have been locked for more than an hour by weakening the functionality of the Lightning port. The vulnerability in Apple’s iOS and iPadOS affects iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later, Apple said. The flaw was surfaced by Bill Marczak, a digital forensic researcher at The Citizen Lab, an organization known for its work finding and confirming the presence of spyware on mobile devices belonging to journalists, dissidents and other members of civil society. Editor's Note: The Cybersecurity and Infrastructure Security Agency (CISA) added the Apple bug (CVE-2025-24200) to its list of Known Exploited Vulnerabilities on February 12.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/apple-ios-vulnerability-citizen-lab