PT-2025-6097 · Apple · Ios +1

Bill Marczak

·

Published

2025-02-10

·

Updated

2025-08-04

·

CVE-2025-24200

CVSS v2.0
6.2
VectorAV:L/AC:H/Au:N/C:C/I:C/A:C

Name of the Vulnerable Software and Affected Versions:

iOS versions prior to 18.3.1

iPadOS versions prior to 18.3.1

iPadOS versions prior to 17.7.5

Description:

A physical attack may disable USB Restricted Mode on a locked device. This issue is related to an authorization problem that has been addressed with improved state management. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals. The vulnerability allows attackers to bypass USB Restricted Mode, which is a security feature designed to prevent data extraction from locked devices.

Recommendations:

To resolve the issue, update your iOS device to version 18.3.1 or later.

To resolve the issue, update your iPadOS device to version 18.3.1 or later.

To resolve the issue, update your iPadOS device to version 17.7.5 or later.

Fix

Improper Authentication

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-01367
CVE-2025-24200

Affected Products

Ios
Ipados