Apple has issued emergency security updates to fix a zero-day vulnerability, CVE-2025-24200, which is being exploited in targeted attacks on iPhone and iPad users.
The vulnerability lets attackers turn off USB Restricted Mode on a locked device, risking unauthorized access to sensitive data. Apple is aware that this issue may have been used in a highly sophisticated attack on certain individuals.
By infosecbulletin
/ Wednesday , July 22 2026
Oracle has fixed over 1,400 security holes in its July 2026 Critical Patch Update (CPU). Most of these flaws were...
Read More
By infosecbulletin
/ Wednesday , July 22 2026
Zimbra has launched updates to fix serious security flaws, including a command injection bug in the SNMP monitoring part. As...
Read More
By infosecbulletin
/ Wednesday , July 22 2026
The Qilin ransomware group is exploiting a flaw in PAN-OS GlobalProtect to break into victims' networks, says the cybersecurity firm...
Read More
By infosecbulletin
/ Saturday , July 18 2026
A new free tool is adding AI helpers into security work. PentestCode is a version of OpenCode made just for...
Read More
By infosecbulletin
/ Saturday , July 18 2026
The WordPress security team received reports about these flaws: CVE-2026-60137 : A facilitated SQL injection issue reported as a team...
Read More
By infosecbulletin
/ Friday , July 17 2026
A Windows security flaw called LegacyHive (MSNightmare) misuses the User Profile Service. This allows local users to gain higher privileges,...
Read More
By infosecbulletin
/ Thursday , July 16 2026
Zoom has issued updates for a flaw in the Windows desktop client, known as CVE-2026-53412. This issue may allow an...
Read More
By infosecbulletin
/ Thursday , July 16 2026
India is speeding up its work to make homegrown AI models for cybersecurity. These models will help protect important digital...
Read More
By infosecbulletin
/ Wednesday , July 15 2026
A serious security flaw in Cursor, a popular AI code editor used by more than 7 million developers, lets attackers...
Read More
By infosecbulletin
/ Wednesday , July 15 2026
Microsoft's Patch Tuesday in July 2026 fixes around 570 security flaws in its products. This comes after June's big update,...
Read More
The company fixed the vulnerability in iOS 18.3.1 and iPadOS 18.3.1 by enhancing state management.
The zero-day vulnerability impacts the following devices:
iPhone XS and later
iPad Pro 13-inch
iPad Pro 12.9-inch (3rd generation and later)
iPad Pro 11-inch (1st generation and later)
iPad Air (3rd generation and later)
iPad (7th generation and later)
iPad mini (5th generation and later)
USB Restricted Mode helps keep your data safe by blocking USB access if your device has been locked for over an hour.
This feature blocks unauthorized access to locked iOS devices to prevent law enforcement from using forensic software. However, a recent vulnerability lets attackers bypass this protection.
Bill Marczak from Citizen Lab, a cybersecurity research group at the University of Toronto, discovered the vulnerability. Citizen Lab is known for identifying advanced cyberattacks.
Apple urges the users to install security updates iOS 18.3.1 and iPadOS 18.3.1 right away to fix the CVE-2025-24200 vulnerability and enhance security.
SAML Bypass Auth on GitHub Enterprise Servers to Login