Apple fixes iPhone and iPad bug used in an "extremely sophisticated attack"

On Monday, Apple released updates for its mobile operating systems for iOS and iPadOS, which fixed a flaw that the company said “may have been exploited in an extremely sophisticated attack against specific targeted individuals.”

Based on its language used in its security update, Apple hints that the attacks were most likely carried out with physical control of a person’s device, meaning whoever was abusing this flaw had to connect to the person’s Apple devices with a forensics device like Cellebrite or Graykey, two systems that allow law enforcement to unlock and access data stored on iPhones and other devices.

Impact: A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

Description: An authorization issue was addressed with improved state management.

CVE-2025-24200: Bill Marczak of The Citizen Lab at The University of Toronto’s Munk School

I’m curious, has Apple ever mentioned an “extremely sophisticated attack” in their release notes before? Not to my knowledge :eyes:

5 Likes

Citizen Lab strikes again with the CVE report!

6 Likes

Cellebrite is having a bad day.

Good

1 Like

Yes this update is recommended for all Apple users. It fixes Critical, Actively Exploited USB Security Flaw.

it is only actively exploited when there’s physical access to the device.
Anywho do still update but point stands.