CVE-2025-24200Patch(apple / ipados)

MEDIUMCVSS 6.1 · MEDIUMCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-03-05. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-863

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-08-10); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_os

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-10: 1Mentions · 2026-09-03: 1Active Exploitation · 2026-08-10: 1Active Exploitation · 2026-09-03: 1Patch / Workaround · 2026-08-10: 1Technical Details · 2026-08-10: 1Technical Details · 2026-09-03: 108-1009-03
Signal classification2 categories
Patch
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-101
Patch1
2026-09-031
Active Exploitation1
Full discourse2 posts
  • Masteador Anteador@s3kmaster
    Active Exploitation

    @Arual_Skizoo @crashouse rxisten vulnerabilidades críticas, como CVE-2025-24200 (que deshabilita el modo de seguridad USB) y fallos en WebKit, que han sido explotados activamente por ciberdelincuentes y grupos patrocinados por estados( cof cof, Israel)

    Post summary

    El mensaje señala que CVE-2025-24200, que desactiva el modo de seguridad USB, ha sido explotado activamente por atacantes y grupos patrocinados por estados.

    1002061
    421 followersView on X
  • Go Vivek Go@GoViRaLFG
    Patch

    This Community Note is wrong. In February 2025, Apple released emergency updates for iOS/iPadOS 18.3.1 to patch CVE-2025-24200, a vulnerability in the logic handling USB connections that was actively used in highly targeted, nation-state-level attacks. https://x.com/itsurprem/status/2086665320392180107

    Post summary

    Apple issued emergency patches for iOS/iPadOS 18.3.1 to address CVE-2025-24200, a USB connection logic flaw that was being actively exploited in nation‑state‑level attacks.

    10000121
    1.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---

Explore more