¡¾·ì϶¹«¸æ¡¿iPhone&iPad USBÏÞ¶ÈÄ£Ê½ÈÆ¹ý·ì϶(CVE-2025-24200)

°ä²¼¹¦·ò 2025-02-11

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

iPhone&iPad USBÏÞ¶ÈÄ£Ê½ÈÆ¹ý·ì϶

CVE   ID

CVE-2025-24200

·ì϶ÀàÐÍ

ÊÚÈ¨ÈÆ¹ý

·¢ÏÖ¹¦·ò

2025-02-11

·ì϶ÆÀ·Ö

7.5

·ì϶µÈ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


iPhoneÊÇÆ»¹û¹«Ë¾ÍƳöµÄÖÇÄÜÊÖ»ú£¬ÈÚºÏÁ˸߻úÄÜÓ²¼þºÍiOS²Ù×÷ϵͳ£¬ÌṩÁ÷³©µÄÓû§ÂÄÀú¡£iPadÊÇÆ»¹ûÍÆ³öµÄƽ°åµçÄÔ£¬´îÔØiPadOSϵͳ£¬ÓµÓдóÆÁÄ»¡¢¸ß·Ö±æÂʺÍ׳´ó´¦ÖÃÄÜÁ¦£¬ºÏÓÃÓÚ³ö²úÁ¦¡¢ÓéÀֺʹ´×÷ÀûÓá£Á½Õß¾ùÖ§³Ö¶àÖÖ´´ÐÂÖ°ÄÜ£¬ÈçFace ID¡¢Apple PayºÍ׳´óµÄÉãÏñͷϵͳ¡£


2025Äê2ÔÂ11ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Æ»¹û¹«Ë¾°ä²¼Á˹ØÓÚCVE-2025-24200·ì϶µÄ°²È«²¼¸æ¡£¸Ã·ì϶ÊÇÒ»¸öÁãÈÕ·ì϶£¬Òѱ»ÓÃÓÚÕë¶ÔÌØ¶¨Ö¸±êµÄ¡°¼«Îª¸´ÔÓ¡±¹¥»÷¡£·ì϶ÔÊÐíÎïÀí¹¥»÷ÈÆ¹ýÉè±¸Ëø¶¨ºóµÄUSBÏÞ¶Èģʽ£¬¶ø¸ÃģʽÊÇiOSµÄÒ»ÏȫְÄÜ£¬Ö¼ÔÚÔ¤·ÀÉ豸ÔÚËø¶¨³¬¹ýÒ»Ó×ʱºóÓëÊý¾ÝÌáÈ¡¹¤¾ß³ÉÁ¢ÏνÓ¡£Õâ´Î·ì϶ԴÓÚÊÚȨÖÎÀíÎÊÌ⣬²¢ÒÑÔÚiOS 18.3.1¡¢iPadOS 18.3.1ºÍiPadOS 17.7.5ÖÐͨ¹ý¸Ä½øµÄ״̬ÖÎÀí½øÐн¨¸´¡£


¶þ¡¢Ó°ÏìÁìÓò


iPhone XS¼°¸ü¸ß°æ±¾

iPad Pro 13Ó¢´ç¼°¸üаæ
iPad Pro 12.9Ó¢´ç3´ú¼°¸üаæ
iPad Pro 11Ó¢´ç1´ú¼°¸üаæ
iPad Air 3´ú¼°¸üаæ
iPad 7´ú¼°¸üаæ
iPad mini 5´ú¼°¸üаæ


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


¸üÐÂÉ豸ÖÁ iOS 18.3.1 »ò iPadOS 18.3.1¡¢17.7.5 °æ±¾£¬½¨¸´ÁËÊÚȨÖÎÀí·ì϶£¬Í¨¹ý¸Ä½ø×´Ì¬ÖÎÀíÀ´¼ÓÇ¿ USB ÏÞ¶ÈģʽµÄ°²È«ÐÔ£¬Ô¤·ÀÎïÀí¹¥»÷ÈÆ¹ý¸Ã±£»¤»úÔì¡£


ÏÂÔØÁ´½Ó£º

https://support.apple.com/


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.4 ²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-day-exploited-in-extremely-sophisticated-attacks/

https://support.apple.com/en-us/122174
https://support.apple.com/en-us/122173