Apple iOS and iPadOS Hidden Photos Album Authentication Bypass Vulnerability

Vulnerability

An authentication bypass vulnerability has been identified in the Photos app on iOS and iPadOS. This issue allows photos in the Hidden Photos Album to be viewed without authentication. The vulnerability is present in iOS 18.4 and iPadOS 18.4, as well as iPadOS 17.7.6.

Impact

Exploitation of this vulnerability allows unauthorized access to photos in the Hidden Photos Album.

Remediation

Users can update to iOS 18.4, iPadOS 18.4, or iPadOS 17.7.6 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.