Apple iPadOS 17.7.5
cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*, +1 more
This vulnerability is being actively exploited in the wild.
A vulnerability has been identified in Apple iOS and iPadOS that allows a physical attack to disable USB Restricted Mode on locked devices. This issue arises from an authorization flaw that has been addressed with improved state management. The vulnerability is present in iOS 18.3.1, iPadOS 18.3.1, and iPadOS 17.7.5. Apple is aware of reports that this vulnerability may have been exploited in a highly sophisticated attack targeting specific individuals.
Exploitation of this vulnerability can lead to the disabling of USB Restricted Mode on a locked device, potentially allowing unauthorized access to the device's data.
Users can update to iOS 18.3.1 or iPadOS 18.3.1 through iTunes or the Software Update feature on their devices. iPadOS 17.7.5 is also available through the same channels. Instructions for checking and applying the update are available on the Apple Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.