CVE-2025-24198

This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker with physical access may be able to use Siri to access sensitive user data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

07 Apr 2025, 13:43

Type Values Removed Values Added
References () https://support.apple.com/en-us/122371 - () https://support.apple.com/en-us/122371 - Vendor Advisory
References () https://support.apple.com/en-us/122372 - () https://support.apple.com/en-us/122372 - Vendor Advisory
References () https://support.apple.com/en-us/122373 - () https://support.apple.com/en-us/122373 - Vendor Advisory
References () https://support.apple.com/en-us/122374 - () https://support.apple.com/en-us/122374 - Vendor Advisory
References () https://support.apple.com/en-us/122375 - () https://support.apple.com/en-us/122375 - Vendor Advisory
Summary
  • (es) Este problema se solucionó restringiendo las opciones disponibles en un dispositivo bloqueado. Este problema se solucionó en macOS Ventura 13.7.5, iOS 18.4 y iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4 y macOS Sonoma 14.7.5. Un atacante con acceso físico podría usar Siri para acceder a datos confidenciales del usuario.
First Time Apple macos
Apple
Apple iphone Os
Apple ipados
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*

01 Apr 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.6
CWE CWE-284

31 Mar 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 23:15

Updated : 2025-04-07 13:43


NVD link : CVE-2025-24198

Mitre link : CVE-2025-24198

CVE.ORG link : CVE-2025-24198


JSON object : View

Products Affected

apple

  • ipados
  • iphone_os
  • macos
CWE
CWE-284

Improper Access Control