CVE-2025-30438
📋 TL;DR
This vulnerability allows a malicious app to dismiss the system notification that appears on the Lock Screen when recording starts, potentially hiding unauthorized recording activity. It affects Apple devices running vulnerable versions of visionOS, macOS, tvOS, iOS, and iPadOS. Users who haven't updated to the patched versions are at risk.
💻 Affected Systems
- visionOS
- macOS
- tvOS
- iOS
- iPadOS
📦 What is this software?
Ipados by Apple
Macos by Apple
macOS is Apple's desktop and laptop operating system powering Mac computers used by millions of professionals, developers, creative professionals, and enterprise users worldwide. Built on a Unix foundation with the Darwin kernel and modern Cocoa frameworks, macOS delivers a seamless ecosystem integr...
Learn more about Macos →Macos by Apple
macOS is Apple's desktop and laptop operating system powering Mac computers used by millions of professionals, developers, creative professionals, and enterprise users worldwide. Built on a Unix foundation with the Darwin kernel and modern Cocoa frameworks, macOS delivers a seamless ecosystem integr...
Learn more about Macos →Macos by Apple
macOS is Apple's desktop and laptop operating system powering Mac computers used by millions of professionals, developers, creative professionals, and enterprise users worldwide. Built on a Unix foundation with the Darwin kernel and modern Cocoa frameworks, macOS delivers a seamless ecosystem integr...
Learn more about Macos →Tvos by Apple
Watchos by Apple
⚠️ Risk & Real-World Impact
Worst Case
An attacker could secretly record audio/video without user awareness, enabling surveillance, data theft, or blackmail.
Likely Case
Malicious apps could hide recording notifications, violating user privacy expectations and potentially capturing sensitive information.
If Mitigated
With proper patching, the notification remains visible, allowing users to be aware of recording activity.
🎯 Exploit Status
Requires user to install a malicious app. No public exploit details available. Apple has addressed this in security updates.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5
Vendor Advisory: https://support.apple.com/en-us/122371
Restart Required: Yes
Instructions:
1. Go to Settings > General > Software Update. 2. Download and install the latest update for your device. 3. Restart your device when prompted.
🔧 Temporary Workarounds
Restrict App Installation Sources
allOnly install apps from the official App Store to reduce risk of malicious apps.
Disable Lock Screen Notifications for Recording
allWhile not ideal, disabling lock screen notifications for recording apps reduces the attack surface.
🧯 If You Can't Patch
- Monitor for suspicious app behavior and review app permissions regularly.
- Implement mobile device management (MDM) to control app installation and enforce security policies.
🔍 How to Verify
Check if Vulnerable:
Check your device version in Settings > General > About. Compare with patched versions listed in the advisory.
Check Version:
Settings > General > About > Version (iOS/iPadOS/tvOS/visionOS) or About This Mac > macOS version
Verify Fix Applied:
After updating, verify the version matches or exceeds the patched versions. Test recording notification behavior.
📡 Detection & Monitoring
Log Indicators:
- Unusual app permission requests for microphone/camera
- Apps attempting to manipulate system notifications
Network Indicators:
- Unexpected data exfiltration from recording apps
SIEM Query:
Search for apps with microphone/camera permissions making unusual system calls or notification dismissals.
🔗 References
- https://support.apple.com/en-us/122371
- https://support.apple.com/en-us/122373
- https://support.apple.com/en-us/122374
- https://support.apple.com/en-us/122375
- https://support.apple.com/en-us/122377
- https://support.apple.com/en-us/122378
- http://seclists.org/fulldisclosure/2025/Apr/10
- http://seclists.org/fulldisclosure/2025/Apr/11
- http://seclists.org/fulldisclosure/2025/Apr/12
- http://seclists.org/fulldisclosure/2025/Apr/13
- http://seclists.org/fulldisclosure/2025/Apr/4
- http://seclists.org/fulldisclosure/2025/Apr/8
- http://seclists.org/fulldisclosure/2025/Apr/9
- https://support.apple.com/en-us/122376