CVE-2025-24104

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4. Restoring a maliciously crafted backup file may lead to modification of protected system files.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:19

Type Values Removed Values Added
Summary (en) This issue was addressed with improved handling of symlinks. This issue is fixed in iPadOS 17.7.4, iOS 18.3 and iPadOS 18.3. Restoring a maliciously crafted backup file may lead to modification of protected system files. (en) This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4. Restoring a maliciously crafted backup file may lead to modification of protected system files.

03 Nov 2025, 21:19

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Jan/14 -

30 Jan 2025, 18:15

Type Values Removed Values Added
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
Summary
  • (es) Este problema se solucionó con una gestión mejorada de los enlaces simbólicos. Este problema se solucionó en iPadOS 17.7.4, iOS 18.3 y iPadOS 18.3. Restaurar un archivo de copia de seguridad manipulado malintencionado puede provocar la modificación de archivos sistema protegidos.
References () https://support.apple.com/en-us/122066 - () https://support.apple.com/en-us/122066 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122067 - () https://support.apple.com/en-us/122067 - Release Notes, Vendor Advisory
First Time Apple iphone Os
Apple
Apple ipados
CWE CWE-59

27 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 22:15

Updated : 2026-04-02 19:19


NVD link : CVE-2025-24104

Mitre link : CVE-2025-24104

CVE.ORG link : CVE-2025-24104


JSON object : View

Products Affected

apple

  • iphone_os
  • ipados
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')