important · Mobile
An ordinary iOS or iPadOS app can modify protected file-system content through MobileBackup.
Affects
Apple iOS and iPadOS, the operating systems on supported iPhones and iPads.
Attacker-controlled app code submits paths to MobileBackup; insufficient validation carries those paths into protected file-system locations.
Detail and 2 sources
Updating closes the documented path on fixed releases, but the continued acceptance of pre-fix images leaves rollback and fleet-completeness questions unresolved.