CVE-2025-24221: High severity apple iPadOS vulnerability
Accessibility. A logging issue was addressed with improved data redaction.
Other sources
Accounts. This issue was addressed with improved data access restriction.
— Apple
This issue was addressed with improved data access restriction. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, visionOS 2.4. Sensitive keychain data may be accessible from an iOS backup.
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.7.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.4 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 18.4 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 18.4 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 17.7.6 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 2.4
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24221
- CVE-2025-24131
- CVE-2025-24270
- CVE-2025-24271
- CVE-2025-24177
- CVE-2025-24179
- CVE-2025-24251
- CVE-2025-31197
- CVE-2025-24252
- CVE-2025-30445
- CVE-2025-24206
- CVE-2025-43205
- CVE-2025-24243
- CVE-2025-24244
- CVE-2025-24237
- CVE-2025-30429
- CVE-2025-24212
- CVE-2025-24215
- CVE-2025-24230
- CVE-2025-24085
- CVE-2025-24190
- CVE-2025-24211
- CVE-2025-31203
- CVE-2024-9681
- CVE-2025-30447
- CVE-2025-24210
- CVE-2025-30432
- CVE-2025-24203
- CVE-2025-27113
- CVE-2024-56171
- CVE-2025-24178
- CVE-2025-30426
- CVE-2025-30428
- CVE-2025-24173
- CVE-2025-24113
- CVE-2025-30471
- CVE-2025-30465
- CVE-2025-30433
- CVE-2025-24198
- CVE-2025-24205
- CVE-2025-24201
- CVE-2025-30425
- CVE-2025-24216
- CVE-2025-24264
- CVE-2025-30427
- CVE-2025-24209
- CVE-2024-54543
- CVE-2024-54534
- CVE-2024-54508
- CVE-2024-54502
- CVE-2025-31202
- CVE-2025-30430
- CVE-2025-24180
- CVE-2025-24163
- CVE-2025-31196
- CVE-2025-24182
- CVE-2025-30439
- CVE-2025-24283
- CVE-2025-24257
- CVE-2024-48958
- CVE-2025-24194
- CVE-2025-31182
- CVE-2025-31199
- CVE-2025-30470
- CVE-2025-24095
- CVE-2025-30466
- CVE-2025-30438
- CVE-2025-24214
- CVE-2025-31184
- CVE-2025-24192
- CVE-2025-24202
- CVE-2025-24097
- CVE-2025-30454
- CVE-2025-31191
- CVE-2025-30456
- CVE-2025-30463
- CVE-2025-30434
- CVE-2025-24238
- CVE-2025-46308
- CVE-2025-24193
- CVE-2025-30469
- CVE-2025-30467
- CVE-2025-31192
- CVE-2025-24167
- CVE-2025-24220
- CVE-2025-30436
- CVE-2025-31183
- CVE-2025-24217
- CVE-2025-24208
Frequently Asked Questions
What is the severity of CVE-2025-24221?
CVE-2025-24221 has been classified as a moderate severity vulnerability due to issues related to data access restriction.
How do I fix CVE-2025-24221?
To fix CVE-2025-24221, update your device to the latest version of iOS, iPadOS, or visionOS as specified in the updates.
What devices are affected by CVE-2025-24221?
CVE-2025-24221 affects multiple Apple devices running iPadOS versions up to 17.7.6 and versions 18.0 to 18.4, along with certain versions of iOS and visionOS.
Is there a known exploit for CVE-2025-24221?
As of now, there are no public reports of exploits leveraging CVE-2025-24221.
What types of issues does CVE-2025-24221 address?
CVE-2025-24221 addresses issues related to accessibility logging and data access restrictions that can potentially expose sensitive information.