Coverage › CVE-2025-24200
CVE-2025-24200 Mapped Mobile only
Apple iOS and iPadOS Incorrect Authorization Vulnerability
- Vendor / product
- Apple — iOS and iPadOS
- Description (CISA)
- Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.
- Added to KEV
- 2025-02-12
- Due date
- 2025-03-05
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Known ransomware use
- Unknown
- CWE
- CWE-863
- CISA notes
- https://support.apple.com/en-us/122173
https://nvd.nist.gov/vuln/detail/CVE-2025-24200 - Elsewhere
- cve.org · NVD · CISA KEV · JSON
ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28
3 mapping objects across 3 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such. Mappings marked mobile refer to ATT&CK Mobile; this site traverses the Enterprise bundle only and shows no detection chain for them.
| Technique | Mapping type | CTID comment | Status in v19.2 |
|---|---|---|---|
| T1461 Lockscreen Bypassmobile | exploitation technique | Attackers with physical access to Apple systems were able to bypass USB restricted mode via a maliciously crafted photo or video to conduct targeted surveillance. ref 1 · ref 2 |
not checked (Mobile) |
| T1458 Replication Through Removable Mediamobile | secondary impact | Attackers with physical access to Apple systems were able to bypass USB restricted mode via a maliciously crafted photo or video to conduct targeted surveillance. ref 1 · ref 2 |
not checked (Mobile) |
| T1629 Impair Defensesmobile | primary impact | Attackers with physical access to Apple systems were able to bypass USB restricted mode via a maliciously crafted photo or video to conduct targeted surveillance. ref 1 · ref 2 |
not checked (Mobile) |
Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources
No live Enterprise technique to traverse.