State Issues in macOS - CVE-2025-30430
Published: April 1, 2025
Vulnerability details
The vulnerability allows an attacker to gain unauthorized access to third-party services.
The vulnerability exists in Authentication Services due to software autofill passwords after failing authentication. An attacker with physical access to the system can login to a third-party application using credentials provided by Authentication Services.
Affected software
visionOS
watchOS
Apple iOS
iPadOS
How to mitigate CVE-2025-30430
visionOS - update to 2.4
watchOS - update to 11.4
Apple iOS - update to 18.4 22E240
iPadOS - update to 18.4 22E240