Apple launches iOS 18.3.1 and other updates to fix an active exploited vulnerability and squish other bugs

Download Apple’s iOS and iPadOS 18.3.1, watchOS 11.3.1, macOS Sequoia 15.3.1 and visionOS 2.3.1 updates to fix an actively exploited vulnerability.

The iPhone's Settings icon with red badge, set against a gray background

Apple launched iOS 18.3.1 and other updates on Monday, February 10, 2025, a week after releasing iOS 18.3. You should download and install iOS 18.3.1 as soon as possible to fix a vulnerability that has been actively exploited. Apple did not release matching updates for Apple TV, HomePod or AirPods alongside iOS 18.3.1.

Apple says the updates provide “important security fixes” and recommends all users get them. Security notes on Apple’s website reveal that iOS 18.3.1 fixes an issue where a physical attack may disable USB Restricted Mode on a locked device.

iOS 18.3.1 fixes an actively exploited vulnerability on iPhone

“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals,” says the document. “An authorization issue was addressed with improved state management,” it reads. The company has released the same fix for older iPad models with iPadOS 17.7.5.

USB Restricted Mode prevents accessories from connecting to your iPhone while the device is locked to avoid passcode attacks via specialized hardware like GrayKey boxes. It’s turned on by default, but you can turn it off (not recommended) by going to Settings > Face ID & Passcode and turning on the Allow Access When Locked option under the Allow Access When Locked heading.

To get the updates, open the Settings app on your iPhone or iPad or the System Settings app on your Mac, then navigate to General > Software Update and follow the onscreen instructions. To install the update on your Apple Watch, go to Settings > General > Software Update on the watch or open the companion Watch app on your iPhone, select the My Watch tab and navigate to General > Software Update.

It’s unclear what fixes macOS Sequoia 15.3.1, watchOS 11.3.1 and visionOS 2.3.1 bring as no published CVE entries exist. Whatever fixes they may include, Apple has also made them available on older Mac models with the macOS Ventura 13.7.4 and macOS Sonoma 14.7.4 updates.