NEWS BRIEF Apple has released a security update for a vulnerability that the tech giant reports may have been exploited in an "extremely sophisticated attack." Not only that, but these attacks targeted specific individuals, though Apple has not provided any further information. The vulnerability, tracked as CVE-2025-24200, could allow for a physical attack to disable USB Restricted Mode on a locked device. USB Restricted Mode is a feature that makes it more difficult for threat actors to unlock a user's phone. When active, a phone's lightning port will only allow charging after the device has been locked for more than an hour, meaning that if an unauthorized actor attempted to connect a locked iPhone to a device to access its data, they could only do so with the necessary credentials. The security update to fix this vulnerability is available for iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch third generation and later, iPad Pro 11-inch first generation and later, iPad Air third generation and later, iPad seventh generation and later, and iPad mini fifth generation and later. Users of any of these devices should install updates as soon as possible and can check if they're updated to the latest software version by going to their settings. These kinds of vulnerabilities are usually deployed by commercial spyware vendors, such as Pegasus, to target particular individuals, so the average user shouldn't be concerned about being targeted while the details of the attack r...
Apple Releases Urgent Patch for USB Vulnerability
Dark Reading
·Kristina Beek
·Published Feb 11, 2025
·Updated
Affected Software
12 affected components
Apple iPhone XS
Apple iPad Pro 13-inch
Apple iPad Pro 12.9-inch
Apple iPad Pro 11-inch
Apple iPad Air
Apple iPad
Apple iPad mini
Apple iPhone=XS and later
Apple iPad Pro=13-inch
Apple iPad Pro=12.9-inch third generation and later
Apple iPad Pro=11-inch first generation and later
Apple iPad Air
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Apple's urgent security patch for a USB vulnerability that may have been exploited in sophisticated attacks.
2
What security implications are discussed?
The article highlights that the USB vulnerability could allow attackers to execute malicious code on affected devices.
3
What products or software are affected?
Affected devices include the Apple iPhone XS, various models of iPad Pro, iPad Air, iPad, and iPad mini.
4
Who were the targets of the attacks mentioned in the article?
The attacks targeted specific individuals, although Apple has not disclosed their identities.
5
What should users do in response to this vulnerability?
Users are advised to update their devices immediately to the latest software version to mitigate the risk.