PT-2025-13886 · Apple · Ipados+1

Published

2025-03-31

·

Updated

2025-04-07

·

CVE-2025-24193

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions iOS versions prior to 18.4 iPadOS versions prior to 18.4
Description The issue allows an attacker with a USB-C connection to an unlocked device to programmatically access photos. This is achieved through a lack of proper authentication. The estimated number of potentially affected devices worldwide is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations For iOS versions prior to 18.4, update to iOS 18.4 to resolve the issue. For iPadOS versions prior to 18.4, update to iPadOS 18.4 to resolve the issue.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-05572
CVE-2025-24193

Affected Products

Ios
Ipados