CVE-2025-24200
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Feb 10, 2025
Updated: Feb 18, 2025
CWE ID 863
Summary
CVE-2025-24200 is a vulnerability involving an authorization issue that has been resolved with improved state management in iPadOS 17.7.5, iOS 18.3.1, and iPadOS 18.3.1. This issue allows a physical attacker to bypass USB Restricted Mode on a locked device. Although the specifics of the attack are not publicly disclosed, Apple acknowledges that it may have been exploited in highly sophisticated targeted attacks against select individuals.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- iOS
- iPadOS
- Apple (iPhone OS)
Affected Vendors
- Apple