CVE-2025-24200: medium-severity vulnerability in Apple iPadOS
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
A physical attacker can disable USB Restricted Mode on a locked Apple device, potentially allowing unauthorized access to data through USB connections. This is a serious flaw because it bypasses a key security feature designed to protect phones and tablets when locked.
An authorization bypass in USB Restricted Mode state management allows a local physical attacker with device access to disable the protection mechanism on locked iOS/iPadOS devices. The vulnerability requires physical proximity but can circumvent USB data access restrictions, which is mitigated in iOS 15.8.4+, 16.7.11+, 17.7.5+, and 18.3.1+.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.