CVE Vulnerabilities

CVE-2025-24091

Authentication Bypass by Spoofing

Published: Apr 30, 2025 | Modified: May 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An app may be able to cause a denial-of-service.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

Name Vendor Start Version End Version
Ipados Apple * 17.7.3 (excluding)
Ipados Apple 18.0 (including) 18.3 (excluding)
Iphone_os Apple * 18.3 (including)

References