Executive brief
An incorrect authorization vulnerability in Apple iOS and iPadOS allows a physical attacker to disable USB Restricted Mode on a locked device. The issue was addressed through improved state management to prevent unauthorized access to USB functionality.
Affected products
- Apple iOS < 15.8.4, 16.x < 16.7.11, 17.x < 18.3.1
- Apple iPadOS < 15.8.4, 16.x < 16.7.11, 17.x < 17.7.5, 18.x < 18.3.1
Timeline
- 2025-02-12: disclosed
- 2025-02-12: patched: Fixed in iOS 15.8.4, 16.7.11, 18.3.1 and iPadOS 15.8.4, 16.7.11, 17.7.5, 18.3.1
- 2025-02-12: kev added: Added to CISA KEV catalog
- exploited: Apple reported awareness of extremely sophisticated attacks against specific targeted individuals.