CVE-2025-24200mediumunder attackCWE-863

CVE-2025-24200: medium-severity vulnerability in Apple iPadOS

Published · Updated

43Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Attendcvss 6.1epss 4.4%
from disclosure to weapon
Published on NVDFeb 10
CISA KEV+2d
exploitation probability
4.4%top 9% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2025-03-05

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

A physical attacker can disable USB Restricted Mode on a locked Apple device, potentially allowing unauthorized access to data through USB connections. This is a serious flaw because it bypasses a key security feature designed to protect phones and tablets when locked.

Technical detail

An authorization bypass in USB Restricted Mode state management allows a local physical attacker with device access to disable the protection mechanism on locked iOS/iPadOS devices. The vulnerability requires physical proximity but can circumvent USB data access restrictions, which is mitigated in iOS 15.8.4+, 16.7.11+, 17.7.5+, and 18.3.1+.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N