First published: Mon Feb 10 2025(Updated: )
Accessibility. An authorization issue was addressed with improved state management.
Credit: product-security@apple.com Bill Marczak The Citizen Lab at The University of Toronto
Affected Software | Affected Version | How to fix |
---|---|---|
iPadOS | <17.7.5 | 17.7.5 |
Apple iOS | <18.3.1 | 18.3.1 |
iPadOS | <18.3.1 | 18.3.1 |
Apple iOS and iPadOS | ||
iPadOS | <17.7.5 | |
iPadOS | >=18.0<18.3.1 | |
Apple iPhone OS | <18.3.1 | |
<17.7.5 | ||
>=18.0<18.3.1 | ||
<18.3.1 |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-24200 is classified as high due to the potential for unauthorized access.
To fix CVE-2025-24200, upgrade to iPadOS version 17.7.5 or iOS/iPadOS version 18.3.1.
CVE-2025-24200 is an authorization issue related to state management.
Devices running iPadOS versions before 17.7.5 and iOS/iPadOS versions before 18.3.1 are affected by CVE-2025-24200.
CVE-2025-24200 may allow physical attacks to disable USB Restricted Mode, potentially compromising device security.