Apple has released emergency security updates to fix a zero-day vulnerability used in targeted and "highly sophisticated" attacks , putting iPhone and iPad users at risk .

" A physical attack can disable USB Restricted Mode on a locked device ," the company revealed
See also: XE Hacker Group Exploits VeraCore Zero-Day
USB Restricted Mode is a security feature from Apple, introduced almost seven years ago in iOS 11.4.1. It prevents USB accessories from establishing a data connection if the device has been locked for more than an hour. Thanks to this feature, software like Graykey and Cellebrite, which are commonly used by law enforcement agencies, cannot extract data from locked iPhones and iPads.
In November 2024, Apple introduced another security feature, inactivity reboot, which automatically restarts iPhones after long periods of inactivity to re-encrypt data and make it more difficult for software to extract.
See also: Trimble Cityworks customers warned about Zero-Day
However, the new zero-day vulnerability bypasses these safeguards. The vulnerability is tracked as CVE-2025-24200 and was discovered by Bill Marczak of Citizen Lab. Apple has patched it in iOS 18.3.1, iPadOS 18.3.1, and iPadOS 17.7.5.
There are many Apple devices affected by the zero-day vulnerability, so it is recommended to apply the security updates:
- iPhone XS and later models,
- iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later,
- iPad Pro 12.9-inch 2nd generation, iPad Pro 10.5-inch and iPad 6th generation.
Apple has not provided further information about the exploitation of the zero-day vulnerability.
Last month, Apple patched the first zero-day vulnerability (CVE-2025-24085) of the year, which targeted iPhone users.
See also: 7-Zip MotW bypass used in zero-day attacks against Ukraine

What are the latest techniques for dealing with Zero-Day vulnerabilities?
One of the most modern techniques for dealing with Zero-Day vulnerabilities is the use of artificial intelligence and machine learning to detect and prevent these attacks. These technologies can analyze large volumes of data and identify patterns that could indicate a potential attack.
Additionally, the use of intrusion detection systems (IDS) and intrusion prevention systems (IPS) is another modern technique for dealing with Zero-Day vulnerabilities. These systems can identify and address threats before they affect the system.
Finally, continuous updating and monitoring of systems is essential to protect against Zero-Day vulnerabilities. Updating software and security systems with the latest versions can help prevent attacks, while monitoring systems can allow for the immediate detection and response to any breaches.
Source: www.bleepingcomputer.com
