VYPR
Unrated severityNVD Advisory· Published Dec 11, 2024· Updated Apr 2, 2026

CVE-2024-54503

CVE-2024-54503

Description

In iOS and iPadOS before 18.2, pressing mute during an incoming call may not actually mute the call, potentially allowing unintended audio transmission.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

In iOS and iPadOS before 18.2, pressing mute during an incoming call may not actually mute the call, potentially allowing unintended audio transmission.

Vulnerability

In iOS and iPadOS versions prior to 18.2, an inconsistent user interface issue exists where muting a call while it is ringing may not result in mute being enabled. This affects iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later [1]. The issue is addressed in iOS 18.2 and iPadOS 18.2.

Exploitation

No special attacker position or authentication is required; the issue occurs when a user attempts to mute an incoming call during the ringing phase. The user presses the mute button, but due to the inconsistent UI state, the mute function may not be applied, leaving the microphone active.

Impact

If the mute action fails, the user's audio may be transmitted to the caller despite the user's intention to mute. This could lead to unintended disclosure of private conversations or ambient sounds. The impact is a privacy violation (information disclosure) at the user level.

Mitigation

Apple released iOS 18.2 and iPadOS 18.2 on December 11, 2024, which fix the issue [1]. Users should update their devices to the latest version. No workarounds are documented.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.