Apple iOS and iPadOS Hidden Photos Album Authentication Bypass Vulnerability

Vulnerability

A logic issue allowing unauthorized access to photos in the Hidden Photos Album has been identified in iOS 18.3 and iPadOS 18.3. This vulnerability could be exploited by an attacker with physical access to an unlocked device, enabling them to view photos while the app is locked.

Impact

Exploitation of this vulnerability could lead to unauthorized access to photos in the Hidden Photos Album, bypassing authentication requirements.

Remediation

Users can update to iOS 18.3 or iPadOS 18.3 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.