CVE-2025-30428

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6. Photos in the Hidden Photos Album may be viewed without authentication.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

07 Apr 2025, 14:00

Type Values Removed Values Added
First Time Apple iphone Os
Apple
Apple ipados
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
References () https://support.apple.com/en-us/122371 - () https://support.apple.com/en-us/122371 - Vendor Advisory
References () https://support.apple.com/en-us/122372 - () https://support.apple.com/en-us/122372 - Vendor Advisory

03 Apr 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-305
Summary
  • (es) Este problema se solucionó mejorando la gestión del estado. Este problema se solucionó en iOS 18.4, iPadOS 18.4 y iPadOS 17.7.6. Las fotos del Álbum de Fotos Ocultas se pueden ver sin autenticación.

31 Mar 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 23:15

Updated : 2025-04-07 14:00


NVD link : CVE-2025-30428

Mitre link : CVE-2025-30428

CVE.ORG link : CVE-2025-30428


JSON object : View

Products Affected

apple

  • ipados
  • iphone_os
CWE
CWE-305

Authentication Bypass by Primary Weakness