Apple has released security updates that backport fixes for actively exploited vulnerabilities that were exploited as zero-days to older versions of its operating systems. At the same time, the consumer tech giant released security updates for the latest stable iOS, iPadOS, and macOS, addressing numerous security flaws. The first backport concerns CVE-2025-24200, a flaw discovered by Citizen Lab that was exploited by mobile forensic tools to disable 'USB Restricted Mode' on locked devices. Apple addressed the flaw in iOS 18.3.1, iPadOS 18.3.1, and 17.7.5, released on February 10, 2025. The second vulnerability backported to older OS versions is CVE-2025-24201, which allowed hackers to break out of the Web Content sandbox on the WebKit engine using specially crafted web content. Apple warned that the flaw was exploited in "extremely sophisticated" attacks, fixing it on March 11, 2025, with the release of iOS 18.3.2, iPadOS 18.3.2, macOS Sequoia 15.3.2, visionOS 2.3.2, and Safari 18.3.1. The vendor has now incorporated fixes for both CVE-2025-24200 and CVE-2025-24201 in iOS 16.7.11 and 15.8.4 and iPadOS versions 16.7.11 and 15.8.4. The third flaw fixed on older devices is CVE-2025-24085, a privilege escalation problem in Apple's Core Media framework. The firm fixed the issue in late January 2025 with the release of iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, visionOS 2.3, and tvOS 18.3. Now, fixes for CVE-2025-24085 were made available through iPadOS 17.7.6, and m...
Apple backports zero-day patches to older iPhones and Macs
BleepingComputer
·Bill Toulas
·Published Apr 1, 2025
·Updated
Affected Software
33 affected components
Apple iOS=18.3.1
Apple iPadOS=18.3.1
Apple iPadOS=17.7.5
Apple iOS=18.3.2
Apple iPadOS=18.3.2
Apple macOS=15.3.2
Apple visionOS=2.3.2
Apple Safari=18.3.1
Apple iOS=16.7.11
Apple iOS=15.8.4
Apple iPadOS=16.7.11
Apple iPadOS=15.8.4
Apple iOS=18.3
Apple iPadOS=18.3
Apple macOS=15.3
Apple WatchOS=11.3
Apple visionOS=2.3
Apple tvOS=18.3
Apple iPadOS=17.7.6
Apple macOS=14.7.5
Apple macOS=13.7.5
Apple iOS=18.4
Apple iPadOS=18.4
Apple macOS=15.4
Apple Safari=18.4
Apple iOS=18.3.1
Apple iPadOS=18.3.1
Apple macOS=17.7.5
Apple iOS=18.3.2
Apple iPadOS=18.3.2
Apple macOS=Sequoia 15.3.2
Apple visionOS=2.3.2
Apple Safari=18.3.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Apple's backporting of zero-day security patches to older versions of its operating systems.
2
What types of vulnerabilities are addressed in the security updates?
The security updates address actively exploited vulnerabilities that were previously exploited as zero-days.
3
Which Apple products are affected by these security updates?
The affected products include iPhones, iPads, Macs, and various versions of iOS, iPadOS, macOS, and Safari.
4
What versions of Apple's operating systems received these security patches?
The security patches were released for versions such as iOS 18.3.1, iPadOS 18.3.2, macOS 15.3.2, and more.
5
What is the significance of backporting patches for older devices?
Backporting patches helps protect users of older devices from vulnerabilities that could be exploited by attackers.