Description
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, visionOS 2.4. An app may be able to bypass Privacy preferences.
Published: 2025-03-31
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Privacy Preference Bypass
Action: Immediate Patch
AI Analysis

Impact

A defect in entitlement enforcement allows an application to bypass user‑defined privacy preferences, potentially exposing personal data that the user has restricted. The flaw is a failure to verify required entitlements before granting access to protected resources, which aligns with CWE‑288. An attacker could obtain data such as contacts or location information without the user’s permission, resulting in a confidentiality breach.

Affected Systems

Apple iOS and iPadOS devices running versions prior to 18.4 and Apple visionOS devices prior to 2.4 are affected. The security issue applies to all builds of iOS, iPadOS, and visionOS that lack the latest entitlement checks fixed in the listed releases.

Risk and Exploitability

The vulnerability scores a high CVSS of 7.6, indicating that it is significant if exploited. The EPSS score of less than 1% suggests exploitation likelihood is currently low, but the high severity warrants attention. It is not in the CISA KEV catalog, meaning known exploit code is not publicly documented. The likely attack vector involves a malicious third‑party app installed on the device, which could use the missing entitlement check to read data the user has opted out of. Once the app runs on the device, the restriction can be bypassed without additional user interaction.

Generated by OpenCVE AI on April 28, 2026 at 03:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to iOS 18.4, iPadOS 18.4, or visionOS 2.4 or later, which include the missing entitlement checks.
  • After updating, review installed applications to confirm no legacy app provides unauthorized access to private data.
  • Re‑examine privacy settings for sensitive data to ensure user preferences are honored, and remove any applications that continue to request access against policy.

Generated by OpenCVE AI on April 28, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9029 This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4. An app may be able to bypass Privacy preferences.
History

Tue, 28 Apr 2026 03:45:00 +0000

Type Values Removed Values Added
Title App Bypass of Privacy Preferences via Missing Entitlement Checks

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4. An app may be able to bypass Privacy preferences. This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, visionOS 2.4. An app may be able to bypass Privacy preferences.

Mon, 03 Nov 2025 21:30:00 +0000


Mon, 07 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ipados
Apple iphone Os
Apple visionos
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ipados
Apple iphone Os
Apple visionos

Thu, 03 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-288
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4. An app may be able to bypass Privacy preferences.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:09:21.378Z

Reserved: 2025-01-17T00:00:44.967Z

Link: CVE-2025-24095

cve-icon Vulnrichment

Updated: 2025-04-02T14:12:42.580Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:16.117

Modified: 2026-04-02T19:18:58.623

Link: CVE-2025-24095

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T03:30:19Z

Weaknesses