This issue was addressed with improved handling of symlinks. This issue is fixed in iPadOS 17.7.4, iOS 18.3 and iPadOS 18.3. Restoring a maliciously crafted backup file may lead to modification of protected system files.
CVE ID: CVE-2025-24104
Vendor: Apple
Product: iPadOS
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 17.98% (scored less or equal to compared to others)
EPSS Date: 2025-02-25 (when was this score calculated)