7.5
CVSSv3

CVE-2025-24200

CVSSv4: NA | CVSSv3: 7.5 | CVSSv2: NA | VMScore: 850 | EPSS: 0.25101 | KEV: Exploitation Reported
Published: 10/02/2025 Updated: 11/02/2025

Vulnerability Summary

Authorization Bypass in Apple iOS and iPadOS Enabling USB Restricted Mode Circumvention

Apple addressed an authorization vulnerability in iPadOS 17.7.5, iOS 18.3.1, and iPadOS 18.3.1 that involves potential physical device attacks. The issue allows a physical attacker to potentially disable USB Restricted Mode on a locked device. Apple confirmed they are aware of a report indicating this vulnerability might have been used in a highly complex targeted attack against specific individuals.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple ipados

apple ios and ipados

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-02-10-2025-2 iPadOS 1775 iPadOS 1775 addresses the following issues Information about the security content is also available at supportapplecom/122173 Apple maintains a Security Releases page at supportapplecom/100100 which lists recent software updates with secur ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-02-10-2025-1 iOS 1831 and iPadOS 1831 iOS 1831 and iPadOS 1831 addresses the following issues Information about the security content is also available at supportapplecom/122174 Apple maintains a Security Releases page at supportapplecom/100100 which lists rece ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-03-31-2025-6 iOS 1584 and iPadOS 1584 iOS 1584 and iPadOS 1584 addresses the following issues Information about the security content is also available at supportapplecom/122345 Apple maintains a Security Releases page at supportapplecom/100100 which lists rece ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-03-31-2025-5 iOS 16711 and iPadOS 16711 iOS 16711 and iPadOS 16711 addresses the following issues Information about the security content is also available at supportapplecom/122346 Apple maintains a Security Releases page at supportapplecom/100100 which lists ...

Github Repositories

A variety of tech related news summarized regularly.

News Summary Tech Advancements and Breakthroughs Dancing turtles unlock scientific discovery (comments): Researchers uncover scientific insights through quirky turtle movements Brain Implant That Could Boost Mood By Using Ultrasound To Go Under NHS Trial (comments): A groundbreaking therapy enters clinical trials in the UK Undergraduate Upends a 40-Year-Old Data Science

Recent Articles

Apple fixes two zero-days exploited in targeted iPhone attacks
BleepingComputer • Lawrence Abrams • 16 Apr 2025

Apple fixes two zero-days exploited in targeted iPhone attacks By Lawrence Abrams April 16, 2025 02:06 PM 0 Apple released emergency security updates to patch two zero-day vulnerabilities that were used in an "extremely sophisticated attack" against specific targets' iPhones. The two vulnerabilities are in CoreAudio (CVE-2025-31200) and RPAC (CVE-2025-31201), with both bugs impacting iOS, macOS, tvOS, iPadOS, and visionOS. "Apple is aware of a report that this issue may have been exploited ...

Apple backports zero-day patches to older iPhones and Macs
BleepingComputer • Bill Toulas • 01 Apr 2025

Apple backports zero-day patches to older iPhones and Macs By Bill Toulas April 1, 2025 09:35 AM 0 Apple has released security updates that backport fixes for actively exploited vulnerabilities that were exploited as zero-days to older versions of its operating systems. At the same time, the consumer tech giant released security updates for the latest stable iOS, iPadOS, and macOS, addressing numerous security flaws. Backporting zero-day fixes The first backport concerns CVE-2025-24200, a f...

Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
BleepingComputer • Sergiu Gatlan • 11 Mar 2025

Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks By Sergiu Gatlan March 11, 2025 02:43 PM 0 Apple has released emergency security updates to patch a zero-day bug the company describes as exploited in "extremely sophisticated" attacks. The vulnerability is tracked as CVE-2025-24201 and was found in the WebKit cross-platform web browser engine used by Apple's Safari web browser and many other apps and web browsers on macOS, iOS, Linux, and Windows. "This is a suppleme...

Serbian police used Cellebrite zero-day hack to unlock Android phones
BleepingComputer • Bill Toulas • 28 Feb 2025

Serbian police used Cellebrite zero-day hack to unlock Android phones By Bill Toulas February 28, 2025 11:27 AM 0 Serbian authorities have reportedly used an Android zero-day exploit chain developed by Cellebrite to unlock the device of a student activist in the country and attempt to install spyware. Cellebrite is an Israeli digital forensics company that develops tools used by law enforcement, intelligence agencies, and private companies to extract data from smartphones and other digital ...

Apple fixes zero-day exploited in 'extremely sophisticated' attacks
BleepingComputer • Sergiu Gatlan • 10 Feb 2025

Apple fixes zero-day exploited in 'extremely sophisticated' attacks By Sergiu Gatlan February 10, 2025 02:08 PM 0 Apple has released emergency security updates to patch a zero-day vulnerability that the company says was exploited in targeted and "extremely sophisticated" attacks. "A physical attack may disable USB Restricted Mode on a locked device," the company revealed in an advisory targeting iPhone and iPad users.  "Apple is aware of a report that this issue may have been exploited in a...

Apple belatedly patches actively exploited bugs in older OSes
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Cupertino already squashed 'em in more recent releases - which this week get a fresh round of fixes

Apple has delivered a big batch of OS updates, some of which belatedly patch older versions of its operating systems to address exploited-in-the-wild flaws the iGiant earlier fixed in more recent releases. The most significant fix addresses CVE-2025-24200, a hole in USB Restricted Mode – the security feature introduced back in 2018 to lock down the Lightning or USB-C port if an iDevice has been locked for over an hour. The vulnerability allowed attackers with physical access to a locked device...