CVE-2025-24200: Apple iOS and iPadOS Incorrect Authorization Vulnerability
Accessibility. An authorization issue was addressed with improved state management.
Other sources
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
— MITRE
Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.
— CISA
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.7.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.3.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.8.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.7.11 - Upgrade
Upgrade
Apple iOSto a version that resolves this vulnerability.Fixed in 15.8.4 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 15.8.4 - Upgrade
Upgrade
Apple iOSto a version that resolves this vulnerability.Fixed in 16.7.11 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 16.7.11 - Upgrade
Upgrade
Apple iOSto a version that resolves this vulnerability.Fixed in 18.3.1 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 18.3.1 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 17.7.5 - Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-24200?
The severity of CVE-2025-24200 is classified as high due to the potential for unauthorized access.
How do I fix CVE-2025-24200?
To fix CVE-2025-24200, upgrade to iPadOS version 17.7.5 or iOS/iPadOS version 18.3.1.
What type of vulnerability is CVE-2025-24200?
CVE-2025-24200 is an authorization issue related to state management.
Are my devices affected by CVE-2025-24200?
Devices running iPadOS versions before 17.7.5 and iOS/iPadOS versions before 18.3.1 are affected by CVE-2025-24200.
What impact does CVE-2025-24200 have on device security?
CVE-2025-24200 may allow physical attacks to disable USB Restricted Mode, potentially compromising device security.