Improper authentication in Apple iOS and iPadOS - CVE-2025-24141

 

Improper authentication in Apple iOS and iPadOS - CVE-2025-24141

Published: January 27, 2025


Vulnerability identifier: #VU103331
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-24141
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to bypass lock screen.

The vulnerability exists due to improper authentication within the Accessibility feature. An attacker with physical access to device can access Photos while the app is locked.


Affected software

Apple iOS
iPadOS

How to mitigate CVE-2025-24141

Install updates from vendor's website.

Apple iOS - update to 18.3 22D60
iPadOS - update to 18.3 22D60

External References

Related Security Bulletins