An authorization issue was addressed with improved state management. This issue is fixed in iPadOS 17.7.5, iOS 18.3.1 and iPadOS 18.3.1. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://support.apple.com/en-us/122173 | release notes vendor advisory |
https://support.apple.com/en-us/122174 | release notes vendor advisory |
http://seclists.org/fulldisclosure/2025/Feb/7 | mailing list third party advisory |
http://seclists.org/fulldisclosure/2025/Feb/8 | mailing list third party advisory |