Get the latest tech news

Apple Fixes Zero-Day Exploited In 'Extremely Sophisticated' Attacks


Apple has released emergency security updates for iOS 18.3.1 and iPadOS 18.3.1 to patch a zero-day vulnerability (CVE-2025-24200) that was exploited in "extremely sophisticated," targeted attacks. The flaw, which allowed a physical attack to disable USB Restricted Mode on locked devices, was discove...

The flaw, which allowed a physical attack to disable USB Restricted Mode on locked devices, was discovered by Citizen Lab and may have been used in spyware campaigns; users are strongly advised to install the update immediately. In November, Apple introduced another security feature (dubbed "inactivity reboot") that automatically restarts iPhones after long idle times to re-encrypt data and make it harder to extract by forensic software. The zero-day vulnerability (tracked as CVE-2025-24200 and reported by Citizen Lab's Bill Marczak) patched today by Apple is an authorization issue addressed in iOS 18.3.1 and iPadOS 18.3.1 with improved state management.

Get the Android app

Or read this on Slashdot

Read more on:

Photo of Day

Day

Photo of attacks

attacks

Photo of apple fixes

apple fixes

Related news:

News photo

Apple fixes iPhone and iPad bug used in an ‘extremely sophisticated attack’

News photo

Apple fixes zero-day exploited in 'extremely sophisticated' attacks

News photo

Days after EA CEO suggests players crave live service guff, Kingdom Come: Deliverance 2 boss says their single-player RPG made all its money back in one day