CVE-2024-40851: Apple iPadOS

Low severity, CVSS 2.4. EPSS: 0.3% chance of exploitation in the next 30 days.

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contact photos from the lock screen.

Affected products

  • Apple iPadOS: before 18.1 (fixed in 18.1)
  • Apple iPhone OS: before 18.1 (fixed in 18.1)

Published 2024-10-28. Last modified 2026-06-17.