LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-24200: Apple iOS and iPadOS Incorrect Authorization Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 12, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 5, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-24200 to its Known Exploited Vulnerabilities catalog on Feb 12, 2025, with a federal patch deadline of Mar 5, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.

CVE-2025-24200 is an incorrect authorization vulnerability in Apple iOS and iPadOS. It allows a physical attacker to disable USB Restricted Mode on a locked device. This matters because USB Restricted Mode is intended to limit data connections over USB when a device is locked, reducing the risk of unauthorized access or forensic extraction if the device is lost, stolen, or seized. Organizations that issue or manage iPhones and iPads should treat this as a physical-access risk that can undermine device lock protections.

Public detail is limited to the CISA description and the CWE classification. Confirm exact impact, fixed builds, and any additional conditions against the official Apple security advisory before acting on assumptions.

How it works

The vulnerability is classified as CWE-863 (Incorrect Authorization). In this class of flaw, the software fails to properly enforce authorization checks for a privileged or restricted operation. Here, the affected operation is the ability to disable USB Restricted Mode while the device remains locked.

An attacker with physical possession of a locked iOS or iPadOS device can abuse the incorrect authorization to turn off USB Restricted Mode. Once disabled, the device may accept broader USB data connections that the restricted mode would otherwise block. No remote network exploitation path is described in the available facts; the attack requires physical access. Exact trigger conditions, user interaction requirements, or persistence after reboot are not specified and must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

The vulnerability affects Apple iOS and iPadOS. These operating systems run on iPhone and iPad hardware commonly used as corporate-managed endpoints, BYOD devices, or executive devices that may store sensitive email, credentials, or authentication tokens.

How to remediate

The primary remediation is to apply the vendor update that addresses CVE-2025-24200. Follow Apple’s published instructions for the security update or iOS/iPadOS release that contains the fix. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

If an immediate update is not possible, reduce risk with compensating controls until the patch can be applied.

These measures lower likelihood and impact but do not replace the vendor fix. Plan to apply the official update as soon as operationally feasible.

If your data may have been exposed

Actively exploited vulnerabilities can lead to device compromise and subsequent data exposure. If a device may have been in an attacker’s physical possession while unpatched, treat it as potentially compromised: wipe and re-enroll it after patching, rotate any credentials or tokens that were stored on it, and review access logs for anomalous use of accounts associated with the device. Known ransomware use of this specific vulnerability is not documented. Readers can also run a free exposure scan of their email addresses against known breach data sets to check whether related personal or corporate accounts appear in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · iOS and iPadOS
WeaknessCWE-863
Added to CISA KEVFeb 12, 2025
Federal patch deadlineMar 5, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities