CVE-2025-30430
critical · 9.8This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. Password autofill may fill in passwords after failing authentication.
9.8
CVSS
1.1%
EPSS (exploit prob.)
65th
EPSS percentile
2025-03-31
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-287
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apple | ipados | < 18.4 |
| apple | iphone_os | < 18.4 |
| apple | macos | >= 15.0, < 15.4 |
| apple | visionos | < 2.4 |
Check a specific version with /api/v1/cve/match.
References
- https://support.apple.com/en-us/122371
- https://support.apple.com/en-us/122373
- https://support.apple.com/en-us/122376
- https://support.apple.com/en-us/122378
- http://seclists.org/fulldisclosure/2025/Apr/12
- http://seclists.org/fulldisclosure/2025/Apr/13
- http://seclists.org/fulldisclosure/2025/Apr/4
- http://seclists.org/fulldisclosure/2025/Apr/8
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-30430