Cyber Posture

CVE-2025-24200

MediumCISA KEVActive Exploitation

Published: 10 February 2025

Published
10 February 2025
Modified
03 April 2026
KEV Added
12 February 2025
Patch
CVSS Score 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score 0.4816 97.8th percentile
Risk Priority 61 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-24200 is a medium-severity Incorrect Authorization (CWE-863) vulnerability in Apple Ipados. Its CVSS base score is 6.1 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exfiltration over USB (T1052.001); ranked in the top 2.2% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

The strongest mitigations our analysis identified are NIST 800-53 AC-19 (Access Control for Mobile Devices) and PE-3 (Physical Access Control).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exfiltration over USB (T1052.001). What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Directly addresses the authorization flaw by requiring timely patching of the state management issue fixed in specified iOS/iPadOS updates.

prevent

Prevents the physical access required to exploit the vulnerability and disable USB Restricted Mode on a locked device.

prevent

Enforces usage restrictions and access controls specifically for mobile devices to limit unauthorized USB access and functions on locked iOS/iPadOS devices.

MITRE ATT&CK Enterprise TechniquesAI

T1052.001 Exfiltration over USB Exfiltration
Adversaries may attempt to exfiltrate data over a USB connected physical device.
Why these techniques?

The vulnerability allows physical attackers to disable USB Restricted Mode on a locked device, directly facilitating exfiltration of data over USB physical medium (T1052.001).

Confidence: MEDIUM · MITRE ATT&CK Enterprise v19.0

NVD Description

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on…

more

a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

Deeper analysisAI

CVE-2025-24200 is an authorization vulnerability (CWE-863: Incorrect Authorization) stemming from improper state management, affecting multiple versions of iOS and iPadOS. Specifically, it impacts iOS and iPadOS prior to iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, and iPadOS 17.7.5. The flaw enables a physical attack to disable USB Restricted Mode on a locked device, with a CVSS v3.1 base score of 6.1 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

An attacker with physical access to the device can exploit this vulnerability with low complexity and no privileges or user interaction required. Successful exploitation disables USB Restricted Mode while the device remains locked, potentially granting high-impact access to confidential data and enabling integrity modifications without affecting availability.

Apple's security advisories detail mitigations through updated firmware releases that address the state management issue, including iOS 15.8.4, iPadOS 15.8.4, iOS 16.7.11, iPadOS 16.7.11, iOS 18.3.1, iPadOS 18.3.1, and iPadOS 17.7.5. Practitioners should prioritize patching affected devices, as referenced in Apple support documents such as https://support.apple.com/en-us/122173 and related updates.

Apple has noted awareness of a report indicating this issue may have been exploited in an extremely sophisticated attack targeting specific individuals.

Details

CWE(s)
KEV Date Added
12 February 2025

Affected Products

apple
ipados
≤ 15.8.4 · 16.0 — 16.7.11 · 17.0 — 17.7.5
apple
iphone os
≤ 15.8.4 · 16.0 — 16.7.11 · 17.0 — 18.3.1

CVEs Like This One

CVE-2024-44136Same product: Apple Ipados
CVE-2025-43300Same product: Apple Ipadosboth on KEV
CVE-2025-24221Same product: Apple Ipados
CVE-2024-54512Same product: Apple Ipados
CVE-2024-44238Same product: Apple Ipados
CVE-2024-44276Same product: Apple Ipados
CVE-2025-31229Same product: Apple Ipados
CVE-2026-28858Same product: Apple Ipados
CVE-2026-28874Same product: Apple Ipados
CVE-2026-28875Same product: Apple Ipados

References