CVE-2025-24193: Apple iPadOS

Low severity, CVSS 2.4. EPSS: 0.5% chance of exploitation in the next 30 days.

This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker with a USB-C connection to an unlocked device may be able to programmatically access photos.

Affected products

  • Apple iPadOS: before 18.4 (fixed in 18.4)
  • Apple iPhone OS: before 18.4 (fixed in 18.4)

Published 2025-03-31. Last modified 2026-06-17.