This issue was addressed with improved data access restriction. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6. Sensitive keychain data may be accessible from an iOS backup.
References
| Link | Resource |
|---|---|
| https://support.apple.com/en-us/122371 | Vendor Advisory |
| https://support.apple.com/en-us/122372 | Vendor Advisory |
| https://support.apple.com/en-us/122378 | Vendor Advisory |
| http://seclists.org/fulldisclosure/2025/Apr/12 | |
| http://seclists.org/fulldisclosure/2025/Apr/4 | |
| http://seclists.org/fulldisclosure/2025/Apr/5 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-03-31 23:15
Updated : 2025-11-03 21:19
NVD link : CVE-2025-24221
Mitre link : CVE-2025-24221
CVE.ORG link : CVE-2025-24221
JSON object : View
Products Affected
apple
- ipados
- visionos
- iphone_os
CWE
CWE-863
Incorrect Authorization
