¡¾Îó²îͨ¸æ¡¿iPhone&iPad USBÏÞÖÆÄ£Ê½ÈÆ¹ýÎó²î(CVE-2025-24200)
Ðû²¼Ê±¼ä 2025-02-11Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | iPhone&iPad USBÏÞÖÆÄ£Ê½ÈÆ¹ýÎó²î | ||
CVE ID | CVE-2025-24200 | ||
Îó²îÀàÐÍ | ÊÚÈ¨ÈÆ¹ý | ·¢Ã÷ʱ¼ä | 2025-02-11 |
Îó²îÆÀ·Ö | 7.5 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
iPhoneÊÇÆ»¹û¹«Ë¾ÍƳöµÄÖÇÄÜÊÖ»ú£¬£¬£¬ÈÚºÏÁ˸ßÐÔÄÜÓ²¼þºÍiOS²Ù×÷ϵͳ£¬£¬£¬ÌṩÁ÷ͨµÄÓû§ÌåÑé¡£¡£¡£¡£¡£iPadÊÇÆ»¹ûÍÆ³öµÄƽ°åµçÄÔ£¬£¬£¬´îÔØiPadOSϵͳ£¬£¬£¬¾ßÓдóÆÁÄ»¡¢¸ßÇø·ÖÂʺÍǿʢ´¦Öóͷ£ÄÜÁ¦£¬£¬£¬ÊÊÓÃÓÚÉú²úÁ¦¡¢ÓéÀֺʹ´×÷Ó¦Óᣡ£¡£¡£¡£Á½Õß¾ùÖ§³Ö¶àÖÖÁ¢Ò칦Ч£¬£¬£¬ÈçFace ID¡¢Apple PayºÍǿʢµÄÉãÏñͷϵͳ¡£¡£¡£¡£¡£
2025Äê2ÔÂ11ÈÕ£¬£¬£¬¿Ðý¹ú¼ÊÓÎÏ·¼¯ÍÅVSRC¼à²âµ½Æ»¹û¹«Ë¾Ðû²¼Á˹ØÓÚCVE-2025-24200Îó²îµÄÇ徲ͨ¸æ¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÒ»¸öÁãÈÕÎó²î£¬£¬£¬Òѱ»ÓÃÓÚÕë¶ÔÌØ¶¨Ä¿µÄµÄ¡°¼«ÎªÖØ´ó¡±¹¥»÷¡£¡£¡£¡£¡£Îó²îÔÊÐíÎïÀí¹¥»÷ÈÆ¹ý×°±¸Ëø¶¨ºóµÄUSBÏÞÖÆÄ£Ê½£¬£¬£¬¶ø¸ÃģʽÊÇiOSµÄÒ»ÏîÇå¾²¹¦Ð§£¬£¬£¬Ö¼ÔÚ±ÜÃâ×°±¸ÔÚËø¶¨Áè¼ÝһСʱºóÓëÊý¾ÝÌáÈ¡¹¤¾ß½¨ÉèÅþÁ¬¡£¡£¡£¡£¡£´Ë´ÎÎó²îÔ´ÓÚÊÚȨÖÎÀíÎÊÌ⣬£¬£¬²¢ÒÑÔÚiOS 18.3.1¡¢iPadOS 18.3.1ºÍiPadOS 17.7.5ÖÐͨ¹ýˢеÄ״̬ÖÎÀí¾ÙÐÐÐÞ¸´¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
iPhone XS¼°¸ü¸ß°æ±¾
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º
3.2 ÔÝʱ²½·¥
3.4 ²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-day-exploited-in-extremely-sophisticated-attacks/