CISA Known Exploited Vulnerability (KEV)
Apple iOS and iPadOS Incorrect Authorization Vulnerability
February 12, 2025
March 5, 2025
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
An authorization issue was addressed with improved state management. This issue is fixed in iPadOS 17.7.5, iOS 18.3.1 and iPadOS 18.3.1. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
References
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-863 |
Incorrect Authorization |