Description
An authorization issue was addressed with improved state management. This issue is fixed in iPadOS 17.7.5, iOS 18.3.1 and iPadOS 18.3.1. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
CISA Known Exploited Vulnerability
Date added 2025-02-12 | Due date 2025-03-05
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Problem types
A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Product status
References
seclists.org/fulldisclosure/2025/Feb/7
seclists.org/fulldisclosure/2025/Feb/8
seclists.org/fulldisclosure/2025/Apr/7
www.cisa.gov/...erabilities-catalog?field_cve=CVE-2025-24200
support.apple.com/en-us/122173
support.apple.com/en-us/122174