CISA Known Exploited Vulnerability

CVE-2025-24200

Apple · iOS and iPadOS

Apple iOS and iPadOS Incorrect Authorization Vulnerability

Date added
BOD 22-01 due date
CWE CWE-863
Ransomware Unknown

CISA description

Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.