Newsletter Archives
-
Apple backports fixes
Apple released several updates on March 31, including several backports to older versions of iOS and iPadOS. These fixes retroactively addressed three actively exploited zero-day vulnerabilities affecting legacy versions of its operating systems.
CVE-2025-24200: ” This issue is fixed in iPadOS 17.7.5, iOS 18.3.1 and iPadOS 18.3.1. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.”
That means businesses, journalists, and other highly targeted individuals. It was originally patched on February 10 in iOS 18.3.1, iPadOS 18.3.1, and iPad 17.7.5, but the vulnerability remained unresolved in older operating systems until now.
Another bug, CVE-2025-24201, was patched in iOS 16.7.11, iPadOS 16.7.11, iOS 15.8.4, and iPadOS 15.8.4 and is targeting flaws in WebKit and browsers. It’s been backported to iOS and iPadOS 15 and 16.
For more information, see this post in our forums.