CVE Vulnerabilities

CVE-2025-24206

Authentication Bypass Using an Alternate Path or Channel

Published: Apr 29, 2025 | Modified: Aug 27, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to bypass authentication policy.

Weakness

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Ipados Apple * 17.7.6 (excluding)
Ipados Apple 18.0 (including) 18.4 (excluding)
Iphone_os Apple * 18.4 (excluding)
Macos Apple * 13.7.5 (excluding)
Macos Apple 14.0 (including) 14.7.5 (excluding)
Macos Apple 15.0 (including) 15.4 (excluding)
Tvos Apple * 18.4 (excluding)
Visionos Apple * 2.4 (excluding)

Potential Mitigations

References