CVE-2025-30432

A logic issue was addressed with improved state management. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sonoma 14.7.5. A malicious app may be able to attempt passcode entries on a locked device and thereby cause escalating time delays after 4 failures.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.4 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
appleCNA
---
---
CISA-ADPADP
6.4 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
VendorProductVersion
appleipados
𝑥
< 17.7.6
appleipados
18.0 ≤
𝑥
< 18.4
appleiphone_os
𝑥
< 18.4
applemacos
13.0 ≤
𝑥
< 13.7.5
applemacos
14.0 ≤
𝑥
< 14.7.5
appletvos
𝑥
< 18.4
applevisionos
𝑥
< 2.4
𝑥
= Vulnerable software versions