A serious security vulnerability has been identified in Apple's iOS Activation infrastructure, which allows attackers to insert unauthenticated XML data during the initial device setup phase.
See also: Apple fixes serious security flaws in iOS and macOS

This bug, which affects the stable version of iOS 18.5 (until May 2025), exposes millions of devices to potential tampering before activation and persistent configuration corruption, without requiring any form of certification or signature verification.
The vulnerability targets Apple's internal activation point at https://humb.apple.com/humbug/baa, which handles requests during initial setup.
Attackers can exploit this vulnerability by sending malformed XML.plist data, which the server accepts and processes without sufficient verification, allowing unauthorized configuration changes that remain active after the activation phase.
Substack analysts identified this vulnerability through extensive testing of the iOS Activation system, revealing that the server's tolerance for malformed content and support for DOCTYPE declarations create multiple entry points for attacks .
See also: Apple warns of three zero-day flaws

The research demonstrates that the absence of sender verification mechanisms in the activation infrastructure allows silent, arbitrary configuration modifications, without any error message being displayed — neither to the device nor to Apple's tracking systems
The core vulnerability is located in the Activation server's implementation of XML parsing, which does not implement basic security measures considered necessary for processing external data.
When a device begins the activation process, it communicates with backend systemsvia XML-formatted requests, which include device identifiers and provisioning information. Accepting unsigned data from the server allows attackers to create malicious XML documents that modify device settings during activation.
See also: Apple patches third zero-day vulnerability this year
Another worrying aspect of this iOS Activation vulnerability is that, due to the lack of verification and inadequate security checks, attackers can exploit this route not only to temporarily alter device settings, but also to inject malicious code or install persistent malware before the device has even completed activation. This paves the way for much more extensive attacks, which could compromise the security and privacy of users across a wide range of Apple devices.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
