CVE-2025-24200
published 2025-02-10CVE-2025-24200: An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS…
medium6.1CVSS 3.1
AVPACLPRNUINSUCHIHAN
KEV
CISA Known Exploited Vulnerabilitydue 2025-03-05
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.8.4_and_ipados | — | — |
| apple | ios_16.7.11_and_ipados | — | — |
| apple | ios_18.3.1_and_ipados | — | — |
| apple | ios_and_ipados | < 15.8.4 | 15.8.4 |
| apple | ios_and_ipados | < 16.7.11 | 16.7.11 |
| apple | ios_and_ipados | < 18.3.1 | 18.3.1 |
| apple | ipados | < 17.7.5 | 17.7.5 |
| apple | ipados | < 15.8.4 | 15.8.4 |
| apple | ipados | — | — |
| apple | ipados | >= 16.0 < 16.7.11 | 16.7.11 |
| apple | ipados | 17.0 – 17.7.5 | — |
| apple | ipados | >= 18.0 < 18.3.1 | 18.3.1 |
| apple | iphone_os | < 15.8.4 | 15.8.4 |
| apple | iphone_os | >= 16.0 < 16.7.11 | 16.7.11 |
| apple | iphone_os | >= 17.0 < 18.3.1 | 18.3.1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vulncheck6.1MEDIUM
cisa6.1MEDIUM
Apple
CVE-2025-24200: iOS 16.7.11 and iPadOS 16.7.11
vendor_apple·2025-03-31·CVSS 6.1
CVE-2025-24200 [MEDIUM] CVE-2025-24200: iOS 16.7.11 and iPadOS 16.7.11
Apple Security Update: About the security content of iOS 16.7.11 and iPadOS 16.7.11
Product: iOS 16.7.11 and iPadOS
Version: 16.7.11
CVE: CVE-2025-24200
Component: Accessibility
Impact: A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: An authorization issue was addressed with improved state management.
Apple
CVE-2025-24200: iOS 15.8.4 and iPadOS 15.8.4
vendor_apple·2025-03-31·CVSS 6.1
CVE-2025-24200 [MEDIUM] CVE-2025-24200: iOS 15.8.4 and iPadOS 15.8.4
Apple Security Update: About the security content of iOS 15.8.4 and iPadOS 15.8.4
Product: iOS 15.8.4 and iPadOS
Version: 15.8.4
CVE: CVE-2025-24200
Component: Accessibility
Impact: A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: An authorization issue was addressed with improved state management.
CISA
Apple iOS and iPadOS Incorrect Authorization Vulnerability
cisa·2025-02-12·CVSS 6.1
CVE-2025-24200 [MEDIUM] CWE-863 Apple iOS and iPadOS Incorrect Authorization Vulnerability
Vulnerability: Apple iOS and iPadOS Incorrect Authorization Vulnerability
Affected: Apple iOS and iPadOS
Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://support.apple.com/en-us/122173 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24200
Remediation Due Date: 2025-03-05
Apple
CVE-2025-24200: iOS 18.3.1 and iPadOS 18.3.1
vendor_apple·2025-02-10·CVSS 6.1
CVE-2025-24200 [MEDIUM] CVE-2025-24200: iOS 18.3.1 and iPadOS 18.3.1
Apple Security Update: About the security content of iOS 18.3.1 and iPadOS 18.3.1
Product: iOS 18.3.1 and iPadOS
Version: 18.3.1
CVE: CVE-2025-24200
Component: Accessibility
Impact: A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: An authorization issue was addressed with improved state management.
Apple
CVE-2025-24200: iPadOS 17.7.5
vendor_apple·2025-02-10·CVSS 6.1
CVE-2025-24200 [MEDIUM] CVE-2025-24200: iPadOS 17.7.5
Apple Security Update: About the security content of iPadOS 17.7.5
Product: iPadOS
Version: 17.7.5
CVE: CVE-2025-24200
Component: Accessibility
Impact: A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: An authorization issue was addressed with improved state management.
GHSA
GHSA-hvw5-4g4q-2h8p: An authorization issue was addressed with improved state management
ghsa_unreviewed·2025-02-10
CVE-2025-24200 [HIGH] CWE-863 GHSA-hvw5-4g4q-2h8p: An authorization issue was addressed with improved state management
An authorization issue was addressed with improved state management. This issue is fixed in iPadOS 17.7.5, iOS 18.3.1 and iPadOS 18.3.1. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
VulnCheck
Apple iOS and iPadOS Incorrect Authorization Vulnerability
vulncheck·2025·CVSS 6.1
CVE-2025-24200 [MEDIUM] CWE-863 Apple iOS and iPadOS Incorrect Authorization Vulnerability
Apple iOS and iPadOS Incorrect Authorization Vulnerability
Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.
Affected: Apple iOS and iPadOS
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://support.apple.com/en-us/122173; https://support.apple.com/en-us/122174; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://support.apple.com/en-us/122345; https://support.apple.com/en-us/122346; https://www.enisa.europa.eu/sites/default/files/2025-10/ENISA%20Thr
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
blogs_bleepingcomputer·2025-12-12·CVSS 8.8
CVE-2025-43529 [HIGH] Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
## Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
## Lawrence Abrams
CVE-2025-43529 is a WebKit use-after-free remote code execution flaw that can be exploited by processing maliciously crafted web content. Apple says the flaw was discovered by Google’s Threat Analysis Group.
CVE-2025-14174 is a WebKit memory corruption flaw that could lead to memory corruption. Apple says the flaw was discovered by both Apple and Google’s Threat Analysis Group.
Devices impacted by both flaws include:
iPhone 11 and later
iPad Pro 12.9-inch (3rd generation and later)
iPad Pro 11-inch (1st generation and later)
iPad Air (3rd generation and later)
iPad (8th generation and later)
iPad mini (5th generation and later)
Apple has fixed the flaws in iOS 26.2 and iPadOS 26.2, iOS 18.7
Bleepingcomputer
Apple backports zero-day patches to older iPhones and iPads
blogs_bleepingcomputer·2025-09-16·CVSS 10.0
[CRITICAL] Apple backports zero-day patches to older iPhones and iPads
## Apple backports zero-day patches to older iPhones and iPads
## Sergiu Gatlan
An out-of-bounds write occurs when attackers supply maliciously crafted input to a program that causes it to write data outside the allocated memory buffer, potentially triggering crashes, corrupting data, or even allowing remote code execution.
Apple has now addressed this zero-day flaw in iOS 15.8.5 / 16.7.12, as well as iPadOS 15.8.5 / 16.7.12, with improved bounds checks.
"Processing a malicious image file may result in memory corruption. An out-of-bounds write issue was addressed with improved bounds checking," the company said in Monday advisories .
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals."
The lis
Bleepingcomputer
Apple fixes new zero-day flaw exploited in targeted attacks
blogs_bleepingcomputer·2025-08-20·CVSS 10.0
[CRITICAL] Apple fixes new zero-day flaw exploited in targeted attacks
## Apple fixes new zero-day flaw exploited in targeted attacks
## Sergiu Gatlan
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals," the company revealed in security advisories issued on Wednesday.
"An out-of-bounds write issue was addressed with improved bounds checking. Processing a malicious image file may result in memory corruption."
Apple has addressed this issue with improved bounds checking to prevent exploitation in iOS 18.6.2 and iPadOS 18.6.2 , iPadOS 17.7.10 , macOS Sequoia 15.6.1 , macOS Sonoma 14.7.8 , and macOS Ventura 13.7.8 .
The complete list of devices impacted by this zero-day vulnerability is extensive, as the bug impacts both older and newer models, including:
iPhone XS a
Bleepingcomputer
Apple patches security flaw exploited in Chrome zero-day attacks
blogs_bleepingcomputer·2025-07-30·CVSS 8.8
CVE-2025-6558 [HIGH] Apple patches security flaw exploited in Chrome zero-day attacks
## Apple patches security flaw exploited in Chrome zero-day attacks
## Sergiu Gatlan
Vlad Stolyarov and Clément Lecigne of Google's Threat Analysis Group (TAG), a team of security experts dedicated to defending Google customers against state-sponsored attacks, discovered CVE-2025-6558 in June and reported it to the Google Chrome team, who patched it on July 15 and tagged it as actively exploited in attacks.
While Google has yet to provide further information on these attacks, Google TAG frequently discovers zero-day flaws exploited by government-sponsored threat actors in targeted campaigns aimed at deploying spyware on devices of high-risk individuals, including dissidents, opposition politicians, and journalists.
On Tuesday, Apple released WebKit security updates to address the CVE-2
Krebs
Senator Chides FBI for Weak Advice on Mobile Security
blogs_krebs·2025-06-30
Senator Chides FBI for Weak Advice on Mobile Security
Agents with the Federal Bureau of Investigation (FBI) briefed Capitol Hill staff recently on hardening the security of their mobile devices, after a contacts list stolen from the personal phone of the White House Chief of Staff Susie Wiles was reportedly used to fuel a series of text messages and phone calls impersonating her to U.S. lawmakers. But in a letter this week to the FBI, one of the Senate’s most tech-savvy lawmakers says the feds aren’t doing enough to recommend more appropriate security protections that are already built into most consumer mobile devices.
A screenshot of the first page from Sen. Wyden’s letter to FBI Director Kash Patel.
On May 29, The Wall Street Journal reported that federal authorities were investigating a clandestine effort to impersonate Ms. Wiles via te
Krebs
Senator Chides FBI for Weak Advice on Mobile Security
blogs_krebs·2025-06-30
Senator Chides FBI for Weak Advice on Mobile Security
Agents with the Federal Bureau of Investigation (FBI) briefed Capitol Hill staff recently on hardening the security of their mobile devices, after a contacts list stolen from the personal phone of the White House Chief of Staff Susie Wiles was reportedly used to fuel a series of text messages and phone calls impersonating her to U.S. lawmakers. But in a letter this week to the FBI, one of the Senate’s most tech-savvy lawmakers says the feds aren’t doing enough to recommend more appropriate security protections that are already built into most consumer mobile devices.
On May 29, The Wall Street Journal reported that federal authorities were investigating a clandestine effort to impersonate Ms. Wiles via text messages and in phone calls that may have used AI to spoof her voice. According to
Bleepingcomputer
Apple fixes two zero-days exploited in targeted iPhone attacks
blogs_bleepingcomputer·2025-04-16·CVSS 10.0
CVE-2025-31200 [CRITICAL] Apple fixes two zero-days exploited in targeted iPhone attacks
## Apple fixes two zero-days exploited in targeted iPhone attacks
## Lawrence Abrams
The CVE-2025-31200 flaw in CoreAudio was discovered by Apple and the Google Threat Analysis team. It can be exploited by processing an audio stream in a maliciously crafted media file to execute remote code on the device.
The company also fixed CVE-2025-31201, which Apple discovered. It is a bug in RPAC that allows attackers with read or write access to bypass Pointer Authentication (PAC), an iOS security feature that helps protect against memory vulnerabilities.
Apple has not shared further details on how the flaws were exploited in attacks. BleepingComputer contacted Apple and Google with questions about flaws but has not received a response.
Both vulnerabilities were fixed in iOS 18.4.1 , iPadOS 18
Checkpoint
7th April – Threat Intelligence Report
blogs_checkpoint·2025-04-07
CVE-2024-20439 7th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 7th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 7th April, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The second-largest bar association in the US, The State Bar of Texas, has experienced a ransomware attack that resulted in unauthorized access to its network, exposing sensitive member information including full names and legal case documents. The INC ransomware gang claimed responsibility for the attack and has already leaked
Bleepingcomputer
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
blogs_bleepingcomputer·2025-03-11·CVSS 7.8
CVE-2025-24201 [HIGH] Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
## Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
## Sergiu Gatlan
Apple said attackers can exploit the CVE-2025-24201 vulnerability using maliciously crafted web content to break out of the Web Content sandbox.
The company has fixed this out-of-bounds write issue with improved checks to prevent unauthorized actions in iOS 18.3.2, iPadOS 18.3.2 , macOS Sequoia 15.3.2 , visionOS 2.3.2 , and Safari 18.3.1 .
The list of devices impacted by this zero-day is quite extensive, as the bug affects older and newer models, including:
iPhone XS and later,
iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
Macs
Krebs
Microsoft Patch Tuesday, February 2025 Edition
blogs_krebs·2025-02-12·CVSS 7.8
CVE-2025-21418 [HIGH] Microsoft Patch Tuesday, February 2025 Edition
Microsoft today issued security updates to fix at least 56 vulnerabilities in its Windows operating systems and supported software, including two zero-day flaws that are being actively exploited.
All supported Windows operating systems will receive an update this month for a buffer overflow vulnerability that carries the catchy name CVE-2025-21418 . This patch should be a priority for enterprises, as Microsoft says it is being exploited, has low attack complexity, and no requirements for user interaction.
Tenable senior staff research engineer Satnam Narang noted that since 2022, there have been nine elevation of privilege vulnerabilities in this same Windows component — three each year — including one in 2024 that was exploited in the wild as a zero day (CVE-2024-38193).
“CVE-2024-3819
Krebs
Microsoft Patch Tuesday, February 2025 Edition
blogs_krebs·2025-02-12·CVSS 7.8
CVE-2025-21418 [HIGH] Microsoft Patch Tuesday, February 2025 Edition
Microsoft today issued security updates to fix at least 56 vulnerabilities in its Windows operating systems and supported software, including two zero-day flaws that are being actively exploited.
All supported Windows operating systems will receive an update this month for a buffer overflow vulnerability that carries the catchy name CVE-2025-21418. This patch should be a priority for enterprises, as Microsoft says it is being exploited, has low attack complexity, and no requirements for user interaction.
Tenable senior staff research engineer Satnam Narang noted that since 2022, there have been nine elevation of privilege vulnerabilities in this same Windows component — three each year — including one in 2024 that was exploited in the wild as a zero day (CVE-2024-38193).
“CVE-2024-38193
Bleepingcomputer
Apple fixes zero-day exploited in 'extremely sophisticated' attacks
blogs_bleepingcomputer·2025-02-10·CVSS 7.8
[HIGH] Apple fixes zero-day exploited in 'extremely sophisticated' attacks
## Apple fixes zero-day exploited in 'extremely sophisticated' attacks
## Sergiu Gatlan
USB Restricted Mode is a security feature ( introduced almost seven years ago in iOS 11.4.1) that blocks USB accessories from creating a data connection if the device has been locked for over an hour. This feature is designed to block forensic software like Graykey and Cellebrite (commonly used by law enforcement) from extracting data from locked iOS devices.
In November, Apple introduced another security feature (dubbed "inactivity reboot") that automatically restarts iPhones after long idle times to re-encrypt data and make it harder to extract by forensic software.
The zero-day vulnerability (tracked as CVE-2025-24200 and reported by Citizen Lab's Bill Marczak) patched today by Apple is an author
Recorded Future
Rate My Rizz: Elevating Cyber Resilience Beyond Compliance
blogs_recorded_future
Rate My Rizz: Elevating Cyber Resilience Beyond Compliance
# Rate My Rizz
RSA is always a good opportunity to reconnect with industry friends—2025 was no exception. Beneath the marketing avalanche of “AI-enabled everything,” one theme stuck out in conversations with CISOs and defensive leaders: the mounting time and energy spent on cyber audits, reporting, and remediation.
These Enterprise Risk Management (ERM) and Governance, Risk, and Compliance (GRC) efforts are especially demanding in regulated industries. But with mandates like NIS2 and DORA taking effect in Europe—and domestic frameworks like SOX, SOC2, and CMMC still in play—security leaders are spending more time with audit committees than ever before.
## Compliance Theater: Starring the Risk Register
In enterprises, defensive resource allocations are often adjudicated by committees an
Recorded Future
Rate My Rizz: Elevating Cyber Resilience Beyond Compliance
blogs_recorded_future
Rate My Rizz: Elevating Cyber Resilience Beyond Compliance
## Rate My Rizz
RSA is always a good opportunity to reconnect with industry friends—2025 was no exception. Beneath the marketing avalanche of “AI-enabled everything,” one theme stuck out in conversations with CISOs and defensive leaders: the mounting time and energy spent on cyber audits, reporting, and remediation.
These Enterprise Risk Management (ERM) and Governance, Risk, and Compliance (GRC) efforts are especially demanding in regulated industries. But with mandates like NIS2 and DORA taking effect in Europe—and domestic frameworks like SOX , SOC2 , and CMMC still in play—security leaders are spending more time with audit committees than ever before.
## Compliance Theater: Starring the Risk Register
In enterprises, defensive resource allocations are often adjudicated by committees
https://support.apple.com/en-us/122173https://support.apple.com/en-us/122174https://support.apple.com/en-us/122345https://support.apple.com/en-us/122346http://seclists.org/fulldisclosure/2025/Apr/7http://seclists.org/fulldisclosure/2025/Feb/7http://seclists.org/fulldisclosure/2025/Feb/8https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24200
2025-02-10
Published
2025-02-12
Added to CISA KEV