CVE-2025-30436: Apple iPadOS

Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker may be able to use Siri to enable Auto-Answer Calls.

Affected products

  • Apple iPadOS: before 18.4 (fixed in 18.4)
  • Apple iPhone OS: before 18.4 (fixed in 18.4)

Published 2025-05-12. Last modified 2026-06-17.