• News/
  • https://www.bleepingcomputer.com/news/security/apple-backports-zero-day-patches-to-older-iphones-and-macs/

Apple backports zero-day patches to older iPhones and Macs

BleepingComputer
·
Bill Toulas
·
Published Apr 1, 2025
·
Updated

Apple has released security updates that backport fixes for actively exploited vulnerabilities that were exploited as zero-days to older versions of its operating systems. At the same time, the consumer tech giant released security updates for the latest stable iOS, iPadOS, and macOS, addressing numerous security flaws. The first backport concerns CVE-2025-24200, a flaw discovered by Citizen Lab that was exploited by mobile forensic tools to disable 'USB Restricted Mode' on locked devices. Apple addressed the flaw in iOS 18.3.1, iPadOS 18.3.1, and 17.7.5, released on February 10, 2025. The second vulnerability backported to older OS versions is CVE-2025-24201, which allowed hackers to break out of the Web Content sandbox on the WebKit engine using specially crafted web content. Apple warned that the flaw was exploited in "extremely sophisticated" attacks, fixing it on March 11, 2025, with the release of iOS 18.3.2, iPadOS 18.3.2, macOS Sequoia 15.3.2, visionOS 2.3.2, and Safari 18.3.1. The vendor has now incorporated fixes for both CVE-2025-24200 and CVE-2025-24201 in iOS 16.7.11 and 15.8.4 and iPadOS versions 16.7.11 and 15.8.4. The third flaw fixed on older devices is CVE-2025-24085, a privilege escalation problem in Apple's Core Media framework. The firm fixed the issue in late January 2025 with the release of iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, visionOS 2.3, and tvOS 18.3. Now, fixes for CVE-2025-24085 were made available through iPadOS 17.7.6, and m...

Read full article

Affected Software

33 affected components
Apple iOS=18.3.1
Apple iPadOS=18.3.1
Apple iPadOS=17.7.5
Apple iOS=18.3.2
Apple iPadOS=18.3.2
Apple macOS=15.3.2
Apple visionOS=2.3.2
Apple Safari=18.3.1
Apple iOS=16.7.11
Apple iOS=15.8.4
Apple iPadOS=16.7.11
Apple iPadOS=15.8.4
Apple iOS=18.3
Apple iPadOS=18.3
Apple macOS=15.3
Apple WatchOS=11.3
Apple visionOS=2.3
Apple tvOS=18.3
Apple iPadOS=17.7.6
Apple macOS=14.7.5
Apple macOS=13.7.5
Apple iOS=18.4
Apple iPadOS=18.4
Apple macOS=15.4
Apple Safari=18.4
Apple iOS=18.3.1
Apple iPadOS=18.3.1
Apple macOS=17.7.5
Apple iOS=18.3.2
Apple iPadOS=18.3.2
Apple macOS=Sequoia 15.3.2
Apple visionOS=2.3.2
Apple Safari=18.3.1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Apple's backporting of zero-day security patches to older versions of its operating systems.

2

What types of vulnerabilities are addressed in the security updates?

The security updates address actively exploited vulnerabilities that were previously exploited as zero-days.

3

Which Apple products are affected by these security updates?

The affected products include iPhones, iPads, Macs, and various versions of iOS, iPadOS, macOS, and Safari.

4

What versions of Apple's operating systems received these security patches?

The security patches were released for versions such as iOS 18.3.1, iPadOS 18.3.2, macOS 15.3.2, and more.

5

What is the significance of backporting patches for older devices?

Backporting patches helps protect users of older devices from vulnerabilities that could be exploited by attackers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203