Skip to content
COOEY

EXPOSURES › CVE-2025-24200

CVE-2025-24200

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-02-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-24200 ↗
⌖ EXPLOITED IN THE WILD SHAME 50/100 exploited-in-wild

A physical attacker can disable USB Restricted Mode on locked Apple iOS/iPadOS devices due to an authorization flaw, potentially enabling data exfiltration or malicious code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.