Vulnerabilities > CVE-2025-24200 - Incorrect Authorization vulnerability in Apple Ipados

047910
CVSS 6.1 - MEDIUM
Attack vector
PHYSICAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
low complexity
apple
CWE-863

Summary

An authorization issue was addressed with improved state management. This issue is fixed in iPadOS 17.7.5, iOS 18.3.1 and iPadOS 18.3.1. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

Vulnerable Configurations

Part Description Count
OS
Apple
389

Common Weakness Enumeration (CWE)