Release record

iOS 18.3.1

Full article
Public release
Recorded milestones
1
Beta cycle
Average interval
Public release
Feb 10, 2025

Release notes

Overview

Editorial synthesis with inline references and a source ledger when citations are available.

iOS 18.3.1 was a targeted security update. Apple fixed an authorization weakness that could let a physical attack disable USB Restricted Mode on a locked device and said the issue may have been used in a highly targeted, sophisticated attack.[1]

Apple later added a Messages entry for malicious photos or videos shared through an iCloud Link, with the same targeted-exploitation warning. The June addition is recorded as a later bulletin update, not as proof that the item appeared in the original February notice.[2]

Source ledger

References

Sources are linked to the claims they support. Publication and access dates are shown when available.

  1. About the Security Content of iOS 18.3.1 and iPadOS 18.3.1

    Apple Support · 2026-07-29 · Accessibility; CVE-2025-24200

    Back to text ↑
  2. About the Security Content of iOS 18.3.1 and iPadOS 18.3.1

    Apple Support · 2026-07-29 · Messages; CVE-2025-43200; entry added June 11, 2025

    Back to text ↑
  3. About iOS 18 Updates

    Apple Support · 2026-07-29 · iOS 18.3.1

  4. About the Security Content of iOS 18.3.1 and iPadOS 18.3.1

    Apple Support · 2026-07-29 · Released February 10, 2025

Documented & observed

Changes in this version

Source-linked features, fixes, known issues, removals, and community-observed behavior recorded across this version’s appearances and verified builds.

Release changes

Changed in this release

Features, fixes, removals, and regressions first observed in this release record.

security · fixed

USB Restricted Mode bypass fix

documentedconfirmed

Apple corrected a physical-attack path that could disable USB Restricted Mode on a locked device and said it may have been used against specific targeted individuals.

Recorded at Public

  1. [1] About the Security Content of iOS 18.3.1 and iPadOS 18.3.1 · Accessibility; CVE-2025-24200

security · fixed

Messages iCloud Link processing fix

documentedconfirmed

A later addition to Apple’s bulletin documented a fix for processing a maliciously crafted photo or video shared via an iCloud Link and carried a targeted-exploitation warning.

Recorded at Public

  1. [1] About the Security Content of iOS 18.3.1 and iPadOS 18.3.1 · Messages; CVE-2025-43200; entry added June 11, 2025

Milestones

Release history

Every recorded channel appearance in chronological order. Open an appearance for any available build, scope, notes, and sources.

  1. Public release

    Public

    Source-linked recordEditorially verified

    The public iOS 18.3.1 release addressed two vulnerabilities associated with sophisticated attacks against specific targeted individuals; one bulletin entry was added later.

    Availability
    available
    Sources
    4 linked
    Open this appearance

Historical context

Cycle comparison

Pace, intervals, and duration compared with earlier releases on the same platform.

Official release notes