⚠ Actively exploited
Added to CISA KEV on 2025-02-12. Federal agencies required to patch by 2025-03-05. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2025-24200Incorrect Authorization in Apple IOS AND Ipados

Severity
6.1MEDIUMNVD
EPSS
47.3%
top 2.30%
CISA KEV
KEV
Added 2025-02-12
Due 2025-03-05
Exploit
No known exploits
Timeline
PublishedFeb 10
KEV addedFeb 12
KEV dueMar 5
Latest updateDec 12
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 0.9 | Impact: 5.2

Affected Packages4 packages

CVEListV5apple/ipados< 17.7.5
NVDapple/ipados16.016.7.11+3
CVEListV5apple/ios_and_ipados< 15.8.4+2
NVDapple/iphone_os16.016.7.11+2

🔴Vulnerability Details

3
CVEList
CVE-2025-24200: An authorization issue was addressed with improved state management2025-02-10
GHSA
GHSA-hvw5-4g4q-2h8p: An authorization issue was addressed with improved state management2025-02-10
VulnCheck
Apple iOS and iPadOS Incorrect Authorization Vulnerability2025

📋Vendor Advisories

5
Apple
CVE-2025-24200: iOS 16.7.11 and iPadOS 16.7.112025-03-31
Apple
CVE-2025-24200: iOS 15.8.4 and iPadOS 15.8.42025-03-31
CISA
Apple iOS and iPadOS Incorrect Authorization Vulnerability2025-02-12
Apple
CVE-2025-24200: iOS 18.3.1 and iPadOS 18.3.12025-02-10
Apple
CVE-2025-24200: iPadOS 17.7.52025-02-10

🕵️Threat Intelligence

13
Bleepingcomputer
Apple fixes two zero-day flaws exploited in &#039;sophisticated&#039; attacks2025-12-12
Bleepingcomputer
Apple backports zero-day patches to older iPhones and iPads2025-09-16
Bleepingcomputer
Apple fixes new zero-day flaw exploited in targeted attacks2025-08-20
Bleepingcomputer
Apple patches security flaw exploited in Chrome zero-day attacks2025-07-30
Krebs
Senator Chides FBI for Weak Advice on Mobile Security2025-06-30
CVE-2025-24200 — Incorrect Authorization in Apple | cvebase