#VU119989 Path traversal in usbmuxd - CVE-2025-66004
Published: December 16, 2025
usbmuxd
libimobiledevice
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to input validation error when processing directory traversal sequences. A local user can delete and create files named "*.plist" as the "usbmux" user by sending a crafted "SavePairRecord" message to the daemon's world-writable UNIX socket..