CVE-2025-24141

Published at:
2025-01-27T22:15:18.800

Global infos:

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked.

CVE Status: Modified

References:

  • [email protected]
  • Metrics:

    AttributeValue
    Attack ComplexityLOW
    Attack VectorLOCAL
    Availability ImpactNONE
    Base Score3.3
    Base SeverityLOW
    Confidentiality ImpactLOW
    Integrity ImpactNONE
    Privileges RequiredLOW
    ScopeUNCHANGED
    User InteractionNONE
    Vector StringCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
    Exploitability Score1.8
    Impact Score1.4
    Source[email protected]
    TypePrimary

    Links:

    Exploit-db
    Github