¡¾Â©¶´Í¨¸æ¡¿iPhone&iPad USBÏÞÖÆÄ£Ê½ÈÆ¹ý©¶´(CVE-2025-24200)

Ðû²¼Ê±¼ä 2025-02-11

Ò»¡¢Â©¶´¸ÅÊö


©¶´Ãû³Æ

iPhone&iPad USBÏÞÖÆÄ£Ê½ÈÆ¹ý©¶´

CVE   ID

CVE-2025-24200

©¶´ÀàÐÍ

ÊÚÈ¨ÈÆ¹ý

·¢ÏÖʱ¼ä

2025-02-11

©¶´ÆÀ·Ö

7.5

©¶´Æ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


iPhoneÊÇÆ»¹û¹«Ë¾ÍƳöµÄÖÇÄÜÊÖ»ú£¬ÈÚºÏÁ˸ßÐÔÄÜÓ²¼þºÍiOS²Ù×÷ϵͳ£¬ÌṩÁ÷³©µÄÓû§ÌåÑé¡£iPadÊÇÆ»¹ûÍÆ³öµÄƽ°åµçÄÔ£¬´îÔØiPadOSϵͳ£¬¾ßÓдóÆÁÄ»¡¢¸ß·Ö±æÂʺÍÇ¿´ó´¦ÖÃÄÜÁ¦£¬ÊÊÓÃÓÚÉú²úÁ¦¡¢ÓéÀֺʹ´×÷Ó¦Óá£Á½Õß¾ùÖ§³Ö¶àÖÖ´´Ð¹¦Ð§£¬ÈçFace ID¡¢Apple PayºÍÇ¿´óµÄÉãÏñͷϵͳ¡£


2025Äê2ÔÂ11ÈÕ£¬¶«É­Æ½Ì¨¼¯ÍÅVSRC¼à²âµ½Æ»¹û¹«Ë¾Ðû²¼Á˹ØÓÚCVE-2025-24200©¶´µÄÄþ¾²Í¨¸æ¡£¸Ã©¶´ÊÇÒ»¸öÁãÈÕ©¶´£¬Òѱ»ÓÃÓÚÕë¶ÔÌØ¶¨Ä¿±êµÄ¡°¼«ÎªÅÓ´ó¡±¹¥»÷¡£Â©¶´ÔÊÐíÎïÀí¹¥»÷ÈÆ¹ýÉè±¸Ëø¶¨ºóµÄUSBÏÞÖÆÄ£Ê½£¬¶ø¸ÃģʽÊÇiOSµÄÒ»ÏîÄþ¾²¹¦Ð§£¬Ö¼ÔÚ·ÀÖ¹É豸ÔÚËø¶¨Áè¼ÝһСʱºóÓëÊý¾ÝÌáÈ¡¹¤¾ß½¨Á¢Á¬½Ó¡£´Ë´Î©¶´Ô´ÓÚÊÚȨ¹ÜÀíÎÊÌ⣬²¢ÒÑÔÚiOS 18.3.1¡¢iPadOS 18.3.1ºÍiPadOS 17.7.5ÖÐͨ¹ý¸ïеÄ״̬¹ÜÀí½øÐÐÐÞ¸´¡£


¶þ¡¢Ó°Ï췶Χ


iPhone XS¼°¸ü¸ß°æ±¾

iPad Pro 13Ó¢´ç¼°¸üаæ
iPad Pro 12.9Ó¢´ç3´ú¼°¸üаæ
iPad Pro 11Ó¢´ç1´ú¼°¸üаæ
iPad Air 3´ú¼°¸üаæ
iPad 7´ú¼°¸üаæ
iPad mini 5´ú¼°¸üаæ


Èý¡¢Äþ¾²´ëÊ©


3.1 Éý¼¶°æ±¾


¸üÐÂÉ豸ÖÁ iOS 18.3.1 »ò iPadOS 18.3.1¡¢17.7.5 °æ±¾£¬ÐÞ¸´ÁËÊÚȨ¹ÜÀí©¶´£¬Í¨¹ý¸ïÐÂ״̬¹ÜÀíÀ´ÔöÇ¿ USB ÏÞÖÆÄ£Ê½µÄÄþ¾²ÐÔ£¬·ÀÖ¹ÎïÀí¹¥»÷ÈÆ¹ý¸Ã±£»¤»úÖÆ¡£


ÏÂÔØÁ´½Ó£º

https://support.apple.com/


3.2 ÁÙʱ´ëÊ©


ÔÝÎÞ¡£


3.4 ²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-day-exploited-in-extremely-sophisticated-attacks/

https://support.apple.com/en-us/122174
https://support.apple.com/en-us/122173