CVE-2025-24200

medium

Description

An authorization issue was addressed with improved state management. This issue is fixed in iPadOS 17.7.5, iOS 18.3.1 and iPadOS 18.3.1. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

References

https://thehackernews.com/2025/04/apple-patches-two-actively-exploited.html

https://www.bleepingcomputer.com/news/security/apple-fixes-two-zero-days-exploited-in-targeted-iphone-attacks/

https://www.securityweek.com/apple-patches-recent-zero-days-in-older-iphones/

https://www.bleepingcomputer.com/news/security/apple-backports-zero-day-patches-to-older-iphones-and-macs/

https://thehackernews.com/2025/04/apple-backports-critical-fixes-for-3.html

https://cyberscoop.com/apple-security-update-march-2025/

https://support.apple.com/en-us/122346

https://support.apple.com/en-us/122345

https://www.darkreading.com/mobile-security/apple-drops-another-webkit-zero-day-bug

https://www.bleepingcomputer.com/news/apple/apple-fixes-webkit-zero-day-exploited-in-extremely-sophisticated-attacks/

https://thehackernews.com/2025/03/apple-releases-patch-for-webkit-zero.html

https://www.bleepingcomputer.com/news/security/serbian-police-used-cellebrite-zero-day-hack-to-unlock-android-phones/

https://hackread.com/apple-extremely-sophisticated-exploit-ios-security/

https://www.darkreading.com/endpoint-security/apple-releases-urgent-patch-usb-vulnerability

https://www.securityweek.com/apple-confirms-usb-restricted-mode-exploited-in-extremely-sophisticated-attack/

https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-day-exploited-in-extremely-sophisticated-attacks/

https://thehackernews.com/2025/02/apple-patches-actively-exploited-ios.html

https://support.apple.com/en-us/122174

https://support.apple.com/en-us/122173

https://securityaffairs.com/174066/hacking/apple-fixes-iphone-and-ipad-bug-exploited-in-extremely-sophisticated-attacks.html

http://seclists.org/fulldisclosure/2025/Feb/8

http://seclists.org/fulldisclosure/2025/Feb/7

Details

Source: Mitre, NVD

Published: 2025-02-10

Updated: 2025-04-02

Risk Information

CVSS v2

Base Score: 6.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Medium