Apple fixes iPhone and iPad bug actively exploited in ‘extremely sophisticated attacks’
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-41061 | Actively Exploited Wallet Flaw Enables Code Execution on Apple iOS, iPadOS, watchOS Apple patched an input validation flaw (CVE-2023-41061, CWE-20) in the Wallet component of iOS, iPadOS, and watchOS that can allow arbitrary code execution when a user interacts with a maliciously crafted attachment. The attack is local and requires user interaction (CVSS 7.8, AV:L/UI:R), so the victim must open or act on the crafted attachment — typically delivered through messaging or another application — for the exploit to succeed. A successful attack yields code execution on the device, and media reports describe it as having been used in 'extremely sophisticated attacks' chained with other Apple zero-days. Anyone running iPhone OS (iOS), iPadOS, or watchOS versions prior to iOS/iPadOS 16.6.1 and watchOS 9.6.2 is affected, a population on the order of a billion active devices. Apple disclosed the issue as actively exploited, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2023-09-11. Do: Immediately update iPhones and iPads to iOS/iPadOS 16.6.1 or later, and Apple Watch to watchOS 9.6.2 or later. Because the flaw is listed in CISA's KEV catalog and was actively exploited at disclosure, treat patching as urgent for all user fleets, especially high-value targets; until patched, exercise caution with attachments from untrusted sources. No public proof-of-concept is known, but defenders should check fleet OS versions for stragglers on pre-16.6.1 builds. | 7.8 | 4% | KEV |
| massover 1 billion active devices (combined iPhone/iPad/Apple Watch fleet not yet patched) | |
| CVE-2023-41064 | ImageIO Buffer Overflow in Apple iOS, iPadOS, and macOS Allows Code Execution CVE-2023-41064 is a buffer overflow (CWE-120) in the ImageIO component of Apple iOS, iPadOS, and macOS that is triggered when the system processes a maliciously crafted image. Because ImageIO performs image decoding for messaging and web content, an attacker can reach the flaw through attachments or web pages, and successful exploitation may allow arbitrary code execution on the device. The flaw was exploited in the wild as part of a chain with CVE-2023-41061 (WebKit), which public reporting described as a zero-click, spyware-grade compromise chain used against civil-society targets. All users of iPhones, iPads, and Macs running builds released before Apple's September 2023 fixes are affected, making the exposed population extremely large. The vulnerability was added to the CISA KEV catalog on 2023-09-11, carries a high EPSS score of 45.1% (99th percentile), and no standalone public proof-of-concept is known because exploitation is occurring in real-world attacks rather than labs. Do: Apply Apple's September 2023 fixes — iOS and iPadOS 16.6.1 or later and macOS Ventura 13.5.2 or later — across all iPhone, iPad, and Mac fleets, which satisfies the CISA KEV required action. Because the observed in-the-wild chain paired this ImageIO bug with the CVE-2023-41061 WebKit flaw, treat unpatched devices as actively targeted and prioritize high-value users and privileged endpoints. If updates cannot be deployed promptly, follow the KEV guidance to apply vendor mitigations or discontinue use of the affected devices. | 7.8 | 45% | KEV |
| masshundreds of millions of devices (Apple's installed base of active iPhones, iPads, and Macs exceeds 1 billion) | |
| CVE-2025-24085 | Use-After-Free Privilege Escalation in Apple iOS, iPadOS, macOS and Other Platforms CVE-2025-24085 is a use-after-free memory corruption flaw (CWE-416) in multiple Apple operating systems that Apple addressed with improved memory management. It is triggered by a malicious application already running on a vulnerable device, which can exploit the flaw to elevate its privileges. An attacker who tricks a user into installing and running a malicious app could gain elevated rights beyond the app's sandbox. All users of unpatched iPhones, iPads, Macs, Apple TVs, Apple Vision Pro headsets, and Apple Watches are potentially affected, and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-01-29. Apple has confirmed the issue was actively exploited against versions of iOS before iOS 17.2, indicating in-the-wild exploitation, though no public proof-of-concept is known. Do: Update devices to iOS/iPadOS 18.3 (or iPadOS 17.7.6 on older devices), macOS Sequoia 15.3 / Sonoma 14.7.5 / Ventura 13.7.5, tvOS 18.3, visionOS 2.3, and watchOS 11.3 as soon as possible. Because Apple reports active exploitation against iOS versions before 17.2, treat any iPhone or iPad still below iOS 17.2 as at elevated risk and prioritize it for patching. Inventory Apple device fleets via MDM and confirm updated OS builds are deployed, given the CISA KEV listing and the ~18% 30-day EPSS score. | 10.0 | 18% | KEV |
| mass≈1 billion+ devices (Apple's active installed base spans iOS, iPadOS, macOS, watchOS, tvOS, and visionOS) | |
| CVE-2025-24200 | Incorrect Authorization in Apple iOS/iPadOS Lets Attackers Disable USB Restricted Mode CVE-2025-24200 is an incorrect authorization flaw (CWE-863) in Apple iOS and iPadOS, caused by an authorization issue in state management that Apple resolved with improved state handling. An attacker with brief physical access to a locked device can exploit the flaw to disable USB Restricted Mode, the feature that locks down a locked iPhone or iPad's USB data port against accessories after a set period. This allows USB accessories, including data-extraction and attack peripherals, to communicate with the device while it remains locked, with a high confidentiality and integrity impact (CVSS 6.1, physical attack vector). Any iPhone or iPad user running a version prior to the applicable fixed release is affected, with fixes shipped in iOS 15.8.4, iOS 16.7.11, iOS 18.3.1, iPadOS 15.8.4, iPadOS 16.7.11, iPadOS 17.7.5, and iPadOS 18.3.1. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-12. Do: Update iPhones to iOS 15.8.4, iOS 16.7.11, or iOS 18.3.1 and iPads to iPadOS 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable to each device's branch, checking Settings > General > Software Update for unmanaged devices. Because exploitation requires physical access, prioritize high-risk users (executives, journalists, government personnel), confirm no fleet devices remain on unpatched builds, and avoid untrusted USB accessories and charging ports until updated. CISA's KEV listing requires federal agencies to apply the vendor patch per the required action or discontinue use of the product. | 6.1 | 4% | KEV |
| mass≈1 billion+ devices (Apple's active installed base; every iPhone/iPad running a pre-patch iOS/iPadOS release at the time of disclosure) |
Full article689 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 10, 2025

Apple released iOS and iPadOS updates to address a zero-day likely exploited in extremely sophisticated attacks targeting specific individuals.
Apple released emergency security updates to address a zero-day vulnerability, tracked as CVE-2025-24200, that the company believes was exploited in “extremely sophisticated” targeted attacks.
An attacker could have exploited the vulnerability to disable the USB Restricted Mode “on a locked device.”
Apple’s USB Restricted Mode is a security feature introduced in iOS 11.4.1 to protect devices from unauthorized access via the Lightning port.
The USB Restricted Mode disables the data connection of the iPhone’s Lightning port after a specific interval of time, but it doesn’t interrupt the charging process. Any other data transfer would require the user to provide the passcode.
The IT giant fixed the vulnerability with improved state management.
“A physical attack may disable USB Restricted Mode on a locked device,” reads the release notes for iOS 18.3.1 and iPadOS 18.3.1.
“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.”
Bill Marczak of The Citizen Lab at The University of Toronto’s Munk School reported the vulnerability to the IT giant.
The zero-day impacts the following devices: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later.
Apple also released 17.7.5 to address the issues in iPad Pro 12.9-inch 2nd generation, iPad Pro 10.5-inch, and iPad 6th generation.
As usual, Apple did not publicly disclose details about the attacks exploiting the vulnerability or the threat actors responsible.
However, the circumstance that the Citizen Lab researchers discovered the attack suggests that the threat actor may have used a zero-day exploit to deliver commercial spyware in highly targeted attacks. Such kinds of attacks often rely on zero-day exploits to target journalists, dissidents, and opposition politicians with spyware.
Another possibility is that Apple is aware of physical access attacks on some of its devices, likely involving forensic tools like Cellebrite to unlock and extract data.
In September 2023, researchers at Citizen Lab reported that two actively exploited zero-day flaws (CVE-2023-41064 and CVE-2023-41061) fixed by Apple were used to infect devices with NSO Group’s Pegasus spyware.
According to the researchers, the two vulnerabilities were chained as part of a zero-click exploit, named BLASTPASS, used in attacks on iPhones running the latest version of iOS (16.6).
Citizen Lab reported that the exploit was used to install the Pegasus Spyware on the device belonging to an individual employed by a Washington DC-based civil society organization with international offices.
The experts reported that the exploit involved PassKit attachments containing malicious images that were sent to the victim from an attacker’s iMessage account.
In January, Apple released security updates to address 2025’s first zero-day vulnerability, tracked as CVE-2025-24085, actively exploited in attacks targeting iPhone users.
The vulnerability is a privilege escalation vulnerability that impacts the Core Media framework.
“A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.” reads the advisory ([1], [2], [3], [4], [5]) published by the IT giant.
The Apple Core Media framework supports multimedia tasks like playback, recording, and manipulation of audio and video on iOS and macOS devices.
The company addressed the use after free issue with improved memory management.
Threat actors exploited the vulnerability to target devices running iOS before iOS 17.2.
The vulnerability impacts iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later.
Apple addressed the issue with the release of iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, visionOS 2.3, and tvOS 18.3.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, zero-day)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/174066/hacking/apple-fixes-iphone-and-ipad-bug-exploited-in-extremely-sophisticated-attacks.html