important · Mobile — Physical
A physically held, trust-paired iPhone or iPad exposes arbitrary file read and write through MobileBackup.
Affects
Apple iOS and iPadOS, the operating systems on supported iPhones and iPads.
The attacker needs both possession and an existing trust pairing; a path traversal then escapes the backup path and reaches arbitrary files.
Detail and 2 sources
Apple shipped fixed releases, but pre-fix images remain accepted and revocation is incomplete.