CVE-2025-30428
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Mar 31, 2025
Updated: Apr 7, 2025
CWE ID 305
Summary
CVE-2025-30428 is a vulnerability affecting iOS and iPadOS that has been addressed in versions 18.4 and 17.7.6. Prior to these updates, an issue with state management allowed unauthenticated users to access photos in the Hidden Albums. This security flaw, if exploited, could lead to privacy breaches. The vulnerability has been rectified, ensuring the protection of users' hidden photos.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- iOS
- iPadOS
- Apple (iPhone OS)
Affected Vendors
- Apple