CVE Vulnerabilities

CVE-2025-24095

Authentication Bypass Using an Alternate Path or Channel

Published: Mar 31, 2025 | Modified: Apr 07, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4. An app may be able to bypass Privacy preferences.

Weakness

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Ipados Apple * 18.4 (excluding)
Iphone_os Apple * 18.4 (excluding)
Visionos Apple * 2.4 (excluding)

Potential Mitigations

References