This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4. An app may be able to bypass Privacy preferences.
References
Link | Resource |
---|---|
https://support.apple.com/en-us/122371 | Vendor Advisory |
https://support.apple.com/en-us/122378 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
07 Apr 2025, 14:30
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* |
|
First Time |
Apple iphone Os
Apple Apple visionos Apple ipados |
|
References | () https://support.apple.com/en-us/122371 - Vendor Advisory | |
References | () https://support.apple.com/en-us/122378 - Vendor Advisory |
03 Apr 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-288 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.6 |
Summary |
|
31 Mar 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-31 23:15
Updated : 2025-04-07 14:30
NVD link : CVE-2025-24095
Mitre link : CVE-2025-24095
CVE.ORG link : CVE-2025-24095
JSON object : View
Products Affected
apple
- ipados
- iphone_os
- visionos
CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel