¡¾Îó²îͨ¸æ¡¿iPhone&iPad USBÏÞÖÆÄ£Ê½ÈÆ¹ýÎó²î(CVE-2025-24200)

Ðû²¼Ê±¼ä 2025-02-11

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

iPhone&iPad USBÏÞÖÆÄ£Ê½ÈÆ¹ýÎó²î

CVE   ID

CVE-2025-24200

Îó²îÀàÐÍ

ÊÚÈ¨ÈÆ¹ý

·¢Ã÷ʱ¼ä

2025-02-11

Îó²îÆÀ·Ö

7.5

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


iPhoneÊÇÆ»¹û¹«Ë¾ÍƳöµÄÖÇÄÜÊÖ»ú£¬£¬£¬£¬£¬£¬£¬£¬ÈÚºÏÁ˸ßÐÔÄÜÓ²¼þºÍiOS²Ù×÷ϵͳ£¬£¬£¬£¬£¬£¬£¬£¬ÌṩÁ÷ͨµÄÓû§ÌåÑé ¡£¡£¡£¡£¡£¡£iPadÊÇÆ»¹ûÍÆ³öµÄƽ°åµçÄÔ£¬£¬£¬£¬£¬£¬£¬£¬´îÔØiPadOSϵͳ£¬£¬£¬£¬£¬£¬£¬£¬¾ßÓдóÆÁÄ»¡¢¸ßÇø·ÖÂʺÍǿʢ´¦Öóͷ£ÄÜÁ¦£¬£¬£¬£¬£¬£¬£¬£¬ÊÊÓÃÓÚÉú²úÁ¦¡¢ÓéÀֺʹ´×÷Ó¦Óà ¡£¡£¡£¡£¡£¡£Á½Õß¾ùÖ§³Ö¶àÖÖÁ¢Ò칦Ч£¬£¬£¬£¬£¬£¬£¬£¬ÈçFace ID¡¢Apple PayºÍǿʢµÄÉãÏñͷϵͳ ¡£¡£¡£¡£¡£¡£


2025Äê2ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍø¼¯ÍÅVSRC¼à²âµ½Æ»¹û¹«Ë¾Ðû²¼Á˹ØÓÚCVE-2025-24200Îó²îµÄÇ徲ͨ¸æ ¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÒ»¸öÁãÈÕÎó²î£¬£¬£¬£¬£¬£¬£¬£¬Òѱ»ÓÃÓÚÕë¶ÔÌØ¶¨Ä¿µÄµÄ¡°¼«ÎªÖØ´ó¡±¹¥»÷ ¡£¡£¡£¡£¡£¡£Îó²îÔÊÐíÎïÀí¹¥»÷ÈÆ¹ý×°±¸Ëø¶¨ºóµÄUSBÏÞÖÆÄ£Ê½£¬£¬£¬£¬£¬£¬£¬£¬¶ø¸ÃģʽÊÇiOSµÄÒ»ÏîÇå¾²¹¦Ð§£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ±ÜÃâ×°±¸ÔÚËø¶¨Áè¼ÝһСʱºóÓëÊý¾ÝÌáÈ¡¹¤¾ß½¨ÉèÅþÁ¬ ¡£¡£¡£¡£¡£¡£´Ë´ÎÎó²îÔ´ÓÚÊÚȨÖÎÀíÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬²¢ÒÑÔÚiOS 18.3.1¡¢iPadOS 18.3.1ºÍiPadOS 17.7.5ÖÐͨ¹ýˢеÄ״̬ÖÎÀí¾ÙÐÐÐÞ¸´ ¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


iPhone XS¼°¸ü¸ß°æ±¾

iPad Pro 13Ó¢´ç¼°¸üаæ
iPad Pro 12.9Ó¢´ç3´ú¼°¸üаæ
iPad Pro 11Ó¢´ç1´ú¼°¸üаæ
iPad Air 3´ú¼°¸üаæ
iPad 7´ú¼°¸üаæ
iPad mini 5´ú¼°¸üаæ


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¸üÐÂ×°±¸ÖÁ iOS 18.3.1 »ò iPadOS 18.3.1¡¢17.7.5 °æ±¾£¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÊÚȨÖÎÀíÎó²î£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýË¢ÐÂ״̬ÖÎÀíÀ´ÔöÇ¿ USB ÏÞÖÆÄ£Ê½µÄÇå¾²ÐÔ£¬£¬£¬£¬£¬£¬£¬£¬±ÜÃâÎïÀí¹¥»÷ÈÆ¹ý¸Ã±£»£»£»¤»úÖÆ ¡£¡£¡£¡£¡£¡£


ÏÂÔØÁ´½Ó£º

https://support.apple.com/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ ¡£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-day-exploited-in-extremely-sophisticated-attacks/

https://support.apple.com/en-us/122174
https://support.apple.com/en-us/122173