Impact
An authorization issue in Appleās iOS and iPadOS systems was detected, where improper state management could allow an attacker to disable the USB Restricted Mode on a locked device. This flaw could enable the attacker to bypass hardware restrictions and potentially gain unauthorized access or elevate privileges on the affected device. The weakness is classified as CWE-863.
Affected Systems
The flaw affects multiple Apple operating systems, specifically iOS 15.8.4, 16.7.11, 18.3.1 and iPadOS 15.8.4, 16.7.11, 18.3.1, and iPadOS 17.7.5. Devices running any of these firmware versions are vulnerable until updated.
Risk and Exploitability
The CVSS score is 6.1, indicating a moderate severity, but the EPSS score of 47% signals a relatively high probability of exploitation. The vulnerability is listed in the CISA KEV catalog, underscoring that it has been targeted in at least one highly sophisticated attack. The attack vector is inferred to be physical, requiring an attacker to obtain access to the locked device to disable USB Restricted Mode, after which further exploitation may be possible.
OpenCVE Enrichment