¡¾Îó²îͨ¸æ¡¿iPhone&iPad USBÏÞÖÆÄ£Ê½ÈÆ¹ýÎó²î(CVE-2025-24200)
Ðû²¼Ê±¼ä 2025-02-11Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | iPhone&iPad USBÏÞÖÆÄ£Ê½ÈÆ¹ýÎó²î | ||
CVE ID | CVE-2025-24200 | ||
Îó²îÀàÐÍ | ÊÚÈ¨ÈÆ¹ý | ·¢Ã÷ʱ¼ä | 2025-02-11 |
Îó²îÆÀ·Ö | 7.5 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
iPhoneÊÇÆ»¹û¹«Ë¾ÍƳöµÄÖÇÄÜÊÖ»ú£¬£¬£¬£¬£¬£¬ÈÚºÏÁ˸ßÐÔÄÜÓ²¼þºÍiOS²Ù×÷ϵͳ£¬£¬£¬£¬£¬£¬ÌṩÁ÷ͨµÄÓû§ÌåÑé¡£¡£¡£¡£¡£¡£iPadÊÇÆ»¹ûÍÆ³öµÄƽ°åµçÄÔ£¬£¬£¬£¬£¬£¬´îÔØiPadOSϵͳ£¬£¬£¬£¬£¬£¬¾ßÓдóÆÁÄ»¡¢¸ßÇø·ÖÂʺÍǿʢ´¦Öóͷ£ÄÜÁ¦£¬£¬£¬£¬£¬£¬ÊÊÓÃÓÚÉú²úÁ¦¡¢ÓéÀֺʹ´×÷Ó¦Óᣡ£¡£¡£¡£¡£Á½Õß¾ùÖ§³Ö¶àÖÖÁ¢Ò칦Ч£¬£¬£¬£¬£¬£¬ÈçFace ID¡¢Apple PayºÍǿʢµÄÉãÏñͷϵͳ¡£¡£¡£¡£¡£¡£
2025Äê2ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½Æ»¹û¹«Ë¾Ðû²¼Á˹ØÓÚCVE-2025-24200Îó²îµÄÇ徲ͨ¸æ¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÒ»¸öÁãÈÕÎó²î£¬£¬£¬£¬£¬£¬Òѱ»ÓÃÓÚÕë¶ÔÌØ¶¨Ä¿µÄµÄ¡°¼«ÎªÖØ´ó¡±¹¥»÷¡£¡£¡£¡£¡£¡£Îó²îÔÊÐíÎïÀí¹¥»÷ÈÆ¹ý×°±¸Ëø¶¨ºóµÄUSBÏÞÖÆÄ£Ê½£¬£¬£¬£¬£¬£¬¶ø¸ÃģʽÊÇiOSµÄÒ»ÏîÇå¾²¹¦Ð§£¬£¬£¬£¬£¬£¬Ö¼ÔÚ±ÜÃâ×°±¸ÔÚËø¶¨Áè¼ÝһСʱºóÓëÊý¾ÝÌáÈ¡¹¤¾ß½¨ÉèÅþÁ¬¡£¡£¡£¡£¡£¡£´Ë´ÎÎó²îÔ´ÓÚÊÚȨÖÎÀíÎÊÌ⣬£¬£¬£¬£¬£¬²¢ÒÑÔÚiOS 18.3.1¡¢iPadOS 18.3.1ºÍiPadOS 17.7.5ÖÐͨ¹ýˢеÄ״̬ÖÎÀí¾ÙÐÐÐÞ¸´¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
iPhone XS¼°¸ü¸ß°æ±¾
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º
3.2 ÔÝʱ²½·¥
3.4 ²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-day-exploited-in-extremely-sophisticated-attacks/